Repository navigation
feat: add complete permission reports - #133
Conversation
|
Hey, vielen Dank für das gute Telefonat vorhin! Dazu hier noch ein paar Fragen und Anmerkungen zum PR. 1. Versionsnummer
2. Legacy-Parität können wir streichen Der Punkt, über den ich am längsten nachgedacht habe: Auf unserer Seite gibt es keine historischen PHP-Permission-Reports. Der Katalog wird beim ersten Lauf von ct-cli selbst aufgebaut, es existiert also gar nichts, wogegen hier jemand diffen könnte — außer bei dir lokal. Damit kostet die Parität Aufwand ohne Nutzen, und der Konkret: Sonderfall bitte raus. Entweder das leere Set wie jedes andere hashen oder — schöner — für leere Sets gar keinen Fingerprint ausgeben und stattdessen ein explizites Die Aufnahmeregeln würde ich dagegen behalten, nur anders begründen: leere 3. .gitignore Die Ergänzungen überschneiden sich mit denen in #134. Lass uns die in genau einem PR landen. 4. Frage zu
Ansonsten: read-only, keine Änderung an |
…orts # Conflicts: # package-lock.json # src/index.ts # tests/cli.test.ts
|
Addressed the review in
Validation: 964 tests passed (5 skipped) on the PR branch, plus typecheck, lint, format check, build, docs staleness, and |
…a reads Review follow-ups on eqrm#133: - `ct report permissions` creates its output directories. The documented invocation writes into `reports/`, which this branch gitignores and which does not exist in a fresh clone, so the command ran the full live collection and then died with a raw ENOENT. - `fetchChurchAuthMasterData` falls back per FIELD again, not per envelope. `response.data ?? response` rejected a payload split across `data` and the top level, which the code it replaced accepted. - A duplicate authId warns and keeps the first definition instead of throwing. `ct permissions catalog --refresh` is the only way to act on a staleness warning and must degrade, not die, on an instance whose plugin set aliases a right under two modules. - The subject report sorts each hash group's rights and drops exact duplicates. The bullet de-duplication only collapsed adjacent repeats, so a subject whose rows for one right were not contiguous got the same right several times, each with a subset of its objects. The report is now independent of API row order and diff-stable. - docs/handbuch/permissions.md declares src/reports/permissions/** and src/commands/report.ts as sources, so the staleness gate covers the code it documents, and records the new row ordering. Claude-Session: https://claude.ai/code/session_01SaAzHDgDPSvLnfkKcnDj37
# Conflicts: # tests/cli.test.ts
Summary
adopt grantssemanticschurchauth/ajax getMasterDatadecoder between permission reports and catalog capture--by-subject,--by-object, and--by-bothEmpty subjects
ST) and group-type-role (GTRL) subjects are shown explicitly underKeine Berechtigungen, without a misleading hash, because they reveal actionable permission gapsPRS) and concrete group-role (GRRL) subjects are included only when they have at least one direct permission; listing every empty person and role pairing would hide relevant gaps among thousands of irrelevant rowsCLI
For example:
Both reports are generated from one authenticated, read-only collection pass. Generated
reports/output is ignored by Git because it may contain instance-specific data and person names.Validation
npm test— 964 passed, 5 skippednpm run typechecknpm run lintnpm run format:checknpm run buildgit diff --checkFixes #142