feat(drive): UI: prepare right management

This commit is contained in:
Edouard Vanbelle
2026-06-23 20:26:08 +02:00
parent 6f1f44f962
commit 062bcb701b
5 changed files with 357 additions and 40 deletions
+81 -4
View File
@@ -1,15 +1,92 @@
/**
* Drives endpoints. D0 ships read-only listing; mutations (create / rename /
* member changes) land in D2/D3 and will be added here under the same shape.
* Drives endpoints. D0 ships read-only listing; D2 adds the membership API.
* D3 will add the create-shared-drive flow under the same module.
*
* Consumers usually go through the `drives` store (`$lib/stores/drives.svelte`)
* which dedupes the request and caches the list — touch this module directly
* only when bypassing the cache is intentional (e.g. an explicit refresh).
*/
import { apiJson } from '$lib/api/client';
import type { Drive } from '$lib/api/types';
import { apiFetch, apiJson } from '$lib/api/client';
import { getCsrfHeaders } from '$lib/api/csrf';
import type { Drive, DriveMember, DriveMemberSubject, DriveRole } from '$lib/api/types';
const JSON_HEADERS = { 'Content-Type': 'application/json' };
/** `GET /api/drives` — every drive the caller can read, default first by convention. */
export function listDrives(): Promise<Drive[]> {
return apiJson<Drive[]>('/api/drives', { credentials: 'same-origin' });
}
/** `GET /api/drives/{id}/members` — every role grant on the drive. */
export function listDriveMembers(driveId: string): Promise<DriveMember[]> {
return apiJson<DriveMember[]>(`/api/drives/${encodeURIComponent(driveId)}/members`, {
credentials: 'same-origin'
});
}
/**
* `POST /api/drives/{id}/members` — add a member (or refresh an existing
* subject's role; the underlying `set_role` is idempotent via UNIQUE
* `(subject, resource)`).
*
* Refused with 405 on personal drives (immutable membership) and 400 if a
* last-owner demotion would orphan a shared drive.
*/
export async function addDriveMember(
driveId: string,
subject: DriveMemberSubject,
role: DriveRole,
expiresAt?: string | null
): Promise<DriveMember> {
const res = await apiFetch(`/api/drives/${encodeURIComponent(driveId)}/members`, {
method: 'POST',
headers: { ...JSON_HEADERS, ...getCsrfHeaders() },
credentials: 'same-origin',
body: JSON.stringify({ subject, role, expires_at: expiresAt ?? null })
});
if (!res.ok) throw new Error(`add member failed: ${res.status}`);
return (await res.json()) as DriveMember;
}
/**
* `PATCH /api/drives/{id}/members/{kind}/{sid}` — change a member's role.
* Same guards as `addDriveMember` apply.
*/
export async function updateDriveMember(
driveId: string,
subject: DriveMemberSubject,
role: DriveRole,
expiresAt?: string | null
): Promise<DriveMember> {
const url =
`/api/drives/${encodeURIComponent(driveId)}/members/` +
`${encodeURIComponent(subject.type)}/${encodeURIComponent(subject.id)}`;
const res = await apiFetch(url, {
method: 'PATCH',
headers: { ...JSON_HEADERS, ...getCsrfHeaders() },
credentials: 'same-origin',
body: JSON.stringify({ role, expires_at: expiresAt ?? null })
});
if (!res.ok) throw new Error(`update member failed: ${res.status}`);
return (await res.json()) as DriveMember;
}
/**
* `DELETE /api/drives/{id}/members/{kind}/{sid}` — remove a member.
* Idempotent (removing a non-member returns 204). Refused with 400 if it
* would leave a shared drive without an owner.
*/
export async function removeDriveMember(
driveId: string,
subject: DriveMemberSubject
): Promise<void> {
const url =
`/api/drives/${encodeURIComponent(driveId)}/members/` +
`${encodeURIComponent(subject.type)}/${encodeURIComponent(subject.id)}`;
const res = await apiFetch(url, {
method: 'DELETE',
headers: getCsrfHeaders(),
credentials: 'same-origin'
});
if (!res.ok) throw new Error(`remove member failed: ${res.status}`);
}
+33
View File
@@ -199,11 +199,27 @@ export interface SearchResults {
export type DriveKind = 'personal' | 'shared';
/** Role-keyed share strength. Matches `Role` in the backend authz model. */
export type DriveRole = 'owner' | 'editor' | 'contributor' | 'commenter' | 'viewer';
/** Subject of a grant. Mirrors `SubjectDto`. */
export type SubjectKind = 'user' | 'group' | 'token';
export interface DriveMemberSubject {
type: SubjectKind;
id: string;
}
/**
* One row from `GET /api/drives`. Mirrors `DriveDto` in
* `src/application/dtos/drive_dto.rs`. `default_for_user` is the caller's
* id when present, `null`/undefined otherwise — used to pick the default
* personal drive without hard-coding name conventions.
*
* `caller_role` is the strongest role the calling user holds on this drive
* (direct + group-mediated, collapsed). Drives the permission-aware UI
* gating on `/config/drive/<id>` and similar pages. `undefined` in
* contexts where the caller is the granter rather than a member (e.g.
* outgoing-grants listing).
*/
export interface Drive {
id: string;
@@ -216,4 +232,21 @@ export interface Drive {
policies: Record<string, unknown>;
created_at: string;
updated_at: string;
caller_role?: DriveRole | null;
}
/**
* One row from `GET /api/drives/{id}/members`. Mirrors `GrantDto` in
* `src/application/dtos/grant_dto.rs` — the shape is the same as any
* other role-grant; drive membership just constrains `resource.type` to
* `"drive"`.
*/
export interface DriveMember {
id: string;
subject: DriveMemberSubject;
resource: { type: 'drive'; id: string };
role: DriveRole;
granted_by: string;
granted_at: string;
expires_at?: string | null;
}
+12 -2
View File
@@ -62,13 +62,23 @@
onMount(() => {
void drivesStore.load();
});
// Dev/test override — set `localStorage.setItem('oxi-show-drive-picker', '1')`
// from DevTools to force the picker visible even with a single drive (useful
// for testing the UI before D3's shared-drive creation lands). Evaluated once
// at component mount; reload after toggling to apply.
const forceShowPicker = $derived(
typeof localStorage !== 'undefined' && localStorage.getItem('oxi-show-drive-picker') === '1'
);
</script>
<!-- Only show the drive switcher when there's an actual choice to make. With a
single drive (the default personal one) the picker just repeats "Personal"
under the Files nav row, so hide it; it reappears the moment a second drive
(e.g. a shared one) exists. -->
{#if drivesStore.loaded && drivesStore.drives.length > 1}
(e.g. a shared one) exists.
`forceShowPicker` is the localStorage-driven dev override (see script). -->
{#if drivesStore.loaded && (drivesStore.drives.length > 1 || forceShowPicker)}
<ul class="drive-picker" aria-label={t('drive.picker', 'Drives')}>
{#each sortedDrives as d (d.id)}
<li class="drive-picker__row" class:drive-picker__row--active={isActive(d)}>