09985f8a95
this implements first version (manageable only by admin right now)
routes:
GET /api/groups
List subject groups (paginated). Admin-only.
POST /api/groups
Create a new ReBAC subject group. Admin-only. The name must match the RFC 5321 local-part shape and be globally unique (case-insensitive).
GET /api/groups/search
Search non-virtual groups by name substring. Authenticated only (no admin role required) — backs the share-dialog recipient autocomplete.
GET /api/groups/{id}
Fetch a single group's details. Admin-only.
DELETE /api/groups/{id}
Delete a group. Cascades to `subject_group_members` (FK) and to `access_grants` rows referencing this group as a subject. Admin-only.
PATCH /api/groups/{id}
Update a group's metadata. Admin-only. v1 only persists name renames.
GET /api/groups/{id}/effective-members
List every user transitively reached through this group (members of members of members, etc.). Used by admin / audit tooling. Admin-only.
GET /api/groups/{id}/members
List the *direct* members of a group (one level only). Admin-only.
POST /api/groups/{id}/members
Add a member to a group. Exactly one of `user_id` / `group_id` must be provided. Adding a group-member runs a write-time cycle check and a nesting-depth check (max 8). Admin-only.
DELETE /api/groups/{id}/members/group/{gid}
Remove a nested group-member from a group. Admin-only.
DELETE /api/groups/{id}/members/user/{uid}
Remove a user-member from a group. Admin-only.
fix hurl
groups
round
groups
43 lines
1.8 KiB
JavaScript
43 lines
1.8 KiB
JavaScript
// @ts-check
|
|
|
|
/**
|
|
* Inline element representing a ReBAC subject group: user-group icon +
|
|
* the group's name. Used by the share dialog (to display groups as share
|
|
* recipients) and by the group-management view (to display nested-group
|
|
* members).
|
|
*
|
|
* Visually mirrors `createUserVignette` from `./userVignette.js` so a row
|
|
* built from one can swap in the other without layout shift. Picks
|
|
* `fa-user-group` (a *people* icon) rather than `fa-layer-group`, which is
|
|
* reserved across the app for the *grouping operator* on group-by menu pills
|
|
* — keeping the two concepts visually distinct.
|
|
*
|
|
* subject group (this file) fa-user-group
|
|
* grouping operator (group-by pills) fa-layer-group
|
|
*/
|
|
|
|
import { escapeHtml } from '../core/formatters.js';
|
|
|
|
/**
|
|
* Build the inline vignette.
|
|
*
|
|
* @param {string} name
|
|
* Display name of the group (escaped before injection).
|
|
* @param {'xs'|'sm'|'md'|'list'} [size='sm']
|
|
* Matches the size scale of `createUserVignette`. The size class is
|
|
* `user-vignette--${size}`; see `static/css/components/userVignette.css`.
|
|
* @param {{ icon?: string }} [opts]
|
|
* `icon`: FA class string without the `fa-` prefix (defaults to
|
|
* `'fa-user-group'`). Used to signal virtual groups visually — see
|
|
* `groupIconClass()` / `groupIconClassByVirtual()` in `./groupDisplay.js`
|
|
* return a distinct icon for system-wide virtual groups (Internal,
|
|
* future Everyone, …).
|
|
* @returns {HTMLElement}
|
|
*/
|
|
export function createGroupVignette(name, size = 'sm', { icon = 'fa-user-group' } = {}) {
|
|
const el = document.createElement('div');
|
|
el.className = `user-vignette user-vignette-group user-vignette--${size}`;
|
|
el.innerHTML = `<span class="user-vignette__avatar"><i class="fas ${escapeHtml(icon)}"></i></span><span class="user-vignette__name">${escapeHtml(name)}</span>`;
|
|
return el;
|
|
}
|