feat(group): 1st implementation of Groups

this implements first version (manageable only by admin right now)

    routes:

        GET /api/groups
        List subject groups (paginated). Admin-only.

        POST /api/groups
        Create a new ReBAC subject group. Admin-only. The name must match the RFC 5321 local-part shape and be globally unique (case-insensitive).

        GET /api/groups/search
        Search non-virtual groups by name substring. Authenticated only (no admin role required) — backs the share-dialog recipient autocomplete.

        GET /api/groups/{id}
        Fetch a single group's details. Admin-only.

        DELETE /api/groups/{id}
        Delete a group. Cascades to `subject_group_members` (FK) and to `access_grants` rows referencing this group as a subject. Admin-only.

        PATCH /api/groups/{id}
        Update a group's metadata. Admin-only. v1 only persists name renames.

        GET /api/groups/{id}/effective-members
        List every user transitively reached through this group (members of members of members, etc.). Used by admin / audit tooling. Admin-only.

        GET /api/groups/{id}/members
        List the *direct* members of a group (one level only). Admin-only.

        POST /api/groups/{id}/members
        Add a member to a group. Exactly one of `user_id` / `group_id` must be provided. Adding a group-member runs a write-time cycle check and a nesting-depth check (max 8). Admin-only.

        DELETE /api/groups/{id}/members/group/{gid}
        Remove a nested group-member from a group. Admin-only.

        DELETE /api/groups/{id}/members/user/{uid}
        Remove a user-member from a group. Admin-only.

fix hurl

groups

round

groups
This commit is contained in:
Edouard Vanbelle
2026-05-30 23:35:47 +02:00
parent 41356b6490
commit 09985f8a95
54 changed files with 6421 additions and 145 deletions
+35 -2
View File
@@ -131,7 +131,8 @@
"light": "淺色",
"dark": "深色",
"auto": "跟隨系統"
}
},
"manage_groups": "管理群組"
},
"share": {
"dialogTitle": "共享連結",
@@ -336,7 +337,13 @@
"move_error": "移動時出錯",
"empty_name": "名稱不能為空",
"name_exists": "已存在同名檔案或資料夾",
"generic_error": "發生錯誤"
"generic_error": "發生錯誤",
"group_name_invalid": "群組名稱必須符合電子郵件前綴格式(字母、數字、點、連字符、下劃線;1–64 個字元)。",
"group_cycle": "此成員會在群組之間形成循環參照。",
"group_depth_exceeded": "嵌套深度超過允許的最大值(8)。",
"group_virtual_immutable": "「Internal」群組由系統管理,無法修改。",
"group_not_found": "找不到群組。",
"group_name_taken": "已存在同名群組。"
},
"breadcrumb": {
"home": "主頁"
@@ -755,5 +762,31 @@
"today": "今天",
"last7days": "近7天",
"last30days": "近30天"
},
"groups": {
"title": "管理群組",
"create_button": "建立群組",
"create_dialog_title": "新群組",
"edit_dialog_title": "重新命名群組",
"name_label": "名稱",
"name_placeholder": "engineering",
"description_label": "描述(選填)",
"members_section": "成員",
"add_member_placeholder": "新增使用者或群組…",
"no_members": "尚無成員。",
"remove_member": "移除",
"delete_group": "刪除群組",
"delete_confirm": "刪除群組「{name}」?引用此群組的所有授權將被撤銷。",
"empty_state": "尚無群組。",
"load_more": "載入更多",
"back_to_list": "返回",
"loading": "載入中…",
"virtual_badge": "系統",
"member_count_zero": "無成員",
"member_count_one": "1 個成員",
"member_count_other": "{count} 個成員",
"delete_confirm_label": "請輸入群組名稱以確認:",
"delete_confirm_mismatch": "請準確輸入群組名稱以確認。",
"virtual_internal_name": "內部"
}
}