[server/FGA] added make_admin permission #18371
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Adsda an explicit
make_admin
permission, so only admins can make other users admin.Summary generated by Copilot
🤖 Generated by Copilot at 29f38f9
This pull request implements a new authorization system based on spicedb, which supports installation admins, organization-owned users, and spicedb relationships. It refactors and updates the
authorizer.ts
,user-service.ts
, andorganization-service.ts
modules, and adds new files and tests for theSpiceDBAuthorizer
andRelationshipUpdater
classes. It also modifies some interfaces, functions, and configurations in thegitpod-protocol
,projects-service
, andtsconfig.json
files.Related Issue(s)
Fixes #
How to test
Documentation
Preview status
gitpod:summary
Build Options
Build
Run the build with werft instead of GHA
Run Leeway with
--dont-test
Publish
Installer
Add desired feature flags to the end of the line above, space separated
Preview Environment
If enabled this will build
install/preview
If enabled this will create the environment on GCE infra
Valid options are
all
,workspace
,webapp
,ide
,jetbrains
,vscode
,ssh
/hold