Skip to content

Commit

Permalink
Merge pull request #3539 from uselagoon/fix-viewuser-permission
Browse files Browse the repository at this point in the history
fix: permission changes for some organization changes
  • Loading branch information
tobybellwood authored Sep 7, 2023
2 parents face9a1 + a66cc2e commit 35629b1
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 3 deletions.
4 changes: 3 additions & 1 deletion services/api/src/resources/organization/resolvers.ts
Original file line number Diff line number Diff line change
Expand Up @@ -385,7 +385,9 @@ export const getUserByEmailAndOrganizationId: ResolverFn = async (
{ email, organization},
{ sqlClientPool, models, hasPermission },
) => {
await hasPermission('organization', 'viewUser', organization);
await hasPermission('organization', 'viewUser', {
organization: organization
});

try {
const user = await models.UserModel.loadUserByUsername(email);
Expand Down
12 changes: 10 additions & 2 deletions services/api/src/resources/user/resolvers.ts
Original file line number Diff line number Diff line change
Expand Up @@ -233,9 +233,15 @@ export const addUserToOrganization: ResolverFn = async (
owner: false,
}
if (owner) {
await hasPermission('organization', 'addOwner', {
organization: organization
});
updateUser.owner = true
} else {
await hasPermission('organization', 'addViewer', {
organization: organization
});
}
await hasPermission('organization', 'addViewer')
await models.UserModel.updateUser(updateUser);

userActivityLogger(`User added a user to organization '${organizationData.name}'`, {
Expand Down Expand Up @@ -272,7 +278,9 @@ export const removeUserFromOrganization: ResolverFn = async (
username: R.prop('email', userInput),
});

await hasPermission('organization', 'addOwner');
await hasPermission('organization', 'addOwner', {
organization: organization
});

await models.UserModel.updateUser({
id: user.id,
Expand Down

0 comments on commit 35629b1

Please sign in to comment.