2022-09-21 01:20:29 -07:00
|
|
|
/**
|
|
|
|
* Permissions table implementation
|
|
|
|
*
|
|
|
|
* @usage getCredentialPermissions(user, credential).isOwner;
|
|
|
|
*/
|
|
|
|
|
2022-10-18 06:28:21 -07:00
|
|
|
import {IUser, ICredentialsResponse, IRootState, IWorkflowDb} from "@/Interface";
|
2022-11-15 04:25:04 -08:00
|
|
|
import {EnterpriseEditionFeature, PLACEHOLDER_EMPTY_WORKFLOW_ID} from "@/constants";
|
2022-11-04 06:04:31 -07:00
|
|
|
import { useSettingsStore } from "./stores/settings";
|
2022-09-21 01:20:29 -07:00
|
|
|
|
|
|
|
export enum UserRole {
|
|
|
|
InstanceOwner = 'isInstanceOwner',
|
|
|
|
ResourceOwner = 'isOwner',
|
|
|
|
ResourceEditor = 'isEditor',
|
|
|
|
ResourceReader = 'isReader',
|
|
|
|
}
|
|
|
|
|
|
|
|
export type IPermissions = Record<string, boolean>;
|
|
|
|
|
|
|
|
type IPermissionsTableRowTestFn = (permissions: IPermissions) => boolean;
|
|
|
|
|
|
|
|
export interface IPermissionsTableRow {
|
|
|
|
name: string;
|
|
|
|
test: string[] | IPermissionsTableRowTestFn;
|
|
|
|
}
|
|
|
|
|
|
|
|
export type IPermissionsTable = IPermissionsTableRow[];
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Returns the permissions for the given user and resource
|
|
|
|
*
|
|
|
|
* @param user
|
|
|
|
* @param table
|
|
|
|
*/
|
2022-11-15 04:25:04 -08:00
|
|
|
export const parsePermissionsTable = (user: IUser | null, table: IPermissionsTable): IPermissions => {
|
2022-09-21 01:20:29 -07:00
|
|
|
const genericTable = [
|
2022-11-15 04:25:04 -08:00
|
|
|
{ name: UserRole.InstanceOwner, test: () => user?.isOwner },
|
2022-09-21 01:20:29 -07:00
|
|
|
];
|
|
|
|
|
|
|
|
return [
|
|
|
|
...genericTable,
|
|
|
|
...table,
|
|
|
|
].reduce((permissions: IPermissions, row) => {
|
|
|
|
permissions[row.name] = Array.isArray(row.test)
|
|
|
|
? row.test.some((ability) => permissions[ability])
|
|
|
|
: (row.test as IPermissionsTableRowTestFn)(permissions);
|
|
|
|
|
|
|
|
return permissions;
|
|
|
|
}, {});
|
|
|
|
};
|
|
|
|
|
|
|
|
/**
|
|
|
|
* User permissions definition
|
|
|
|
*/
|
|
|
|
|
2022-11-15 04:25:04 -08:00
|
|
|
export const getCredentialPermissions = (user: IUser | null, credential: ICredentialsResponse) => {
|
2022-11-04 06:04:31 -07:00
|
|
|
const settingsStore = useSettingsStore();
|
2022-11-22 03:40:20 -08:00
|
|
|
const isSharingEnabled = settingsStore.isEnterpriseFeatureEnabled(EnterpriseEditionFeature.Sharing);
|
|
|
|
|
2022-09-21 01:20:29 -07:00
|
|
|
const table: IPermissionsTable = [
|
2022-11-22 03:40:20 -08:00
|
|
|
{ name: UserRole.ResourceOwner, test: () => !!(credential && credential.ownedBy && credential.ownedBy.id === user?.id) || !isSharingEnabled },
|
2022-11-15 04:25:04 -08:00
|
|
|
{ name: UserRole.ResourceReader, test: () => !!(credential && credential.sharedWith && credential.sharedWith.find((sharee) => sharee.id === user?.id)) },
|
2022-09-21 01:20:29 -07:00
|
|
|
{ name: 'read', test: [UserRole.ResourceOwner, UserRole.InstanceOwner, UserRole.ResourceReader] },
|
|
|
|
{ name: 'save', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
|
|
|
{ name: 'updateName', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
|
|
|
{ name: 'updateConnection', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'updateSharing', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'updateNodeAccess', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'delete', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
|
|
|
{ name: 'use', test: [UserRole.ResourceOwner, UserRole.ResourceReader] },
|
|
|
|
];
|
|
|
|
|
|
|
|
return parsePermissionsTable(user, table);
|
|
|
|
};
|
2022-10-18 06:28:21 -07:00
|
|
|
|
2022-11-15 04:25:04 -08:00
|
|
|
export const getWorkflowPermissions = (user: IUser | null, workflow: IWorkflowDb) => {
|
|
|
|
const settingsStore = useSettingsStore();
|
2022-11-22 03:40:20 -08:00
|
|
|
const isSharingEnabled = settingsStore.isEnterpriseFeatureEnabled(EnterpriseEditionFeature.WorkflowSharing);
|
2022-11-15 04:25:04 -08:00
|
|
|
const isNewWorkflow = workflow.id === PLACEHOLDER_EMPTY_WORKFLOW_ID;
|
|
|
|
|
2022-10-18 06:28:21 -07:00
|
|
|
const table: IPermissionsTable = [
|
2022-11-22 03:40:20 -08:00
|
|
|
{ name: UserRole.ResourceOwner, test: () => !!(isNewWorkflow || workflow && workflow.ownedBy && workflow.ownedBy.id === user?.id) || !isSharingEnabled },
|
2022-11-15 04:25:04 -08:00
|
|
|
{ name: UserRole.ResourceReader, test: () => !!(workflow && workflow.sharedWith && workflow.sharedWith.find((sharee) => sharee.id === user?.id)) },
|
2022-10-18 06:28:21 -07:00
|
|
|
{ name: 'read', test: [UserRole.ResourceOwner, UserRole.InstanceOwner, UserRole.ResourceReader] },
|
|
|
|
{ name: 'save', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
|
|
|
{ name: 'updateName', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
|
|
|
{ name: 'updateConnection', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'updateSharing', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'updateNodeAccess', test: [UserRole.ResourceOwner] },
|
|
|
|
{ name: 'delete', test: [UserRole.ResourceOwner, UserRole.InstanceOwner] },
|
2022-11-22 03:40:20 -08:00
|
|
|
{ name: 'use', test: [UserRole.ResourceOwner, UserRole.InstanceOwner, UserRole.ResourceReader] },
|
2022-10-18 06:28:21 -07:00
|
|
|
];
|
|
|
|
|
|
|
|
return parsePermissionsTable(user, table);
|
|
|
|
};
|