Skip to content

[fga] more FGA checks and service use #18517

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 15, 2023
Merged

[fga] more FGA checks and service use #18517

merged 1 commit into from
Aug 15, 2023

Conversation

svenefftinge
Copy link
Member

@svenefftinge svenefftinge commented Aug 15, 2023

Description

Summary generated by Copilot

🤖 Generated by Copilot at 3ac3eb7

This pull request implements the user deletion feature and refactors some of the server components to improve authorization and code quality. It adds a new delete permission to the UserPermission type and the User schema in SpiceDB, and uses the Authorizer and the WorkspaceService for permission checks and workspace operations. It also adds new tests for the WorkspaceService methods and refactors some of the existing code to use dependency injection and remove redundancy.

Related Issue(s)

Fixes #

How to test

Documentation

Preview status

gitpod:summary

Build Options

Build
  • /werft with-werft
    Run the build with werft instead of GHA
  • leeway-no-cache
  • /werft no-test
    Run Leeway with --dont-test
Publish
  • /werft publish-to-npm
  • /werft publish-to-jb-marketplace
Installer
  • analytics=segment
  • with-dedicated-emulation
  • workspace-feature-flags
    Add desired feature flags to the end of the line above, space separated
Preview Environment / Integration Tests
  • /werft with-local-preview
    If enabled this will build install/preview
  • /werft with-preview
  • /werft with-large-vm
  • /werft with-gce-vm
    If enabled this will create the environment on GCE infra
  • with-integration-tests=all
    Valid options are all, workspace, webapp, ide, jetbrains, vscode, ssh. If enabled, with-preview and with-large-vm will be enabled.
  • with-monitoring

/hold

@@ -1057,9 +1058,6 @@ export class GitpodServerImpl implements GitpodServerWithTracing, Disposable {
const ws = await this.workspaceService.getWorkspace(user.id, workspaceId);
await this.guardAccess({ kind: "workspace", subject: ws }, "delete");

// for good measure, try and stop running instances
await this.internalStopWorkspace(ctx, user.id, ws, "deleted via API");
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@geropl I deleted this here because it happens as part of deleteWorkspace below.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only difference I see is the "delete via API" is replaced by "deleted via WorkspaceService". But not sure how we used that anyway. 👍

@geropl
Copy link
Member

geropl commented Aug 15, 2023

Taking a closer look now 👀

Copy link
Member

@geropl geropl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM, and tests are 🟢 : ✔️

@geropl
Copy link
Member

geropl commented Aug 15, 2023

@svenefftinge Would be awesome if you could merge this soon so I can rebase 🚀 🤓 🙏

@svenefftinge
Copy link
Member Author

/unhold

@roboquat roboquat merged commit 735bf0e into main Aug 15, 2023
@roboquat roboquat deleted the se/more-fga branch August 15, 2023 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants