fix(identities): clean up partner permissions, limits and directories on identity webhooks - #112
Merged
Merged
Conversation
… on identity webhooks - bump @data-fair/lib-express to 1.26.0 (secret in the x-secret-key header) - rename: the name of a partner organization in the permissions of other owners' processings follows, and so does the limits document - an organization update carrying partners withdraws the partner permissions granted to organizations that are no longer partners - delete: the processings of the identity are removed with their runs and their directory on disk (same cleanup as DELETE /processings/:id, the directory was left behind), the limits too; a deleted organization is pulled from the partner permissions of others; created/updated only keep the id of a deleted user - created/updated name is now optional in the processing schema - identities.api.spec covers renames, the end of a partnership, the user and organization deletions
The shared identities router refuses the calls that come through the proxy, and the other services of the dev environment do not need the webhooks.
…t in the UI A department missing from the complete list sent by simple-directory was deleted: its processings and runs keep the department id but lose departmentName. The UI shows them as "Former department - <id>" (owner avatar, activity, owner filters). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017hqsZKwijEBoB3m3v9srVD
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017hqsZKwijEBoB3m3v9srVD
…n messages The production build uses the runtime-only vue-i18n: inline messages given to useI18n are not compiled and the key was displayed instead of the label. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017hqsZKwijEBoB3m3v9srVD
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Per-service pass of the identities contract work, guided by the
data-fair-identitiesskill of the lib.@data-fair/lib-expressto 1.26.0 (secret accepted in thex-secret-keyheader)partnerpermissions of other owners' processings follows, and so does thelimitsdocumentpartners(sent by simple-directory since #147) withdraws the partner permissions granted to organizations that are no longer partnersdepartmentslist sent by simple-directory was deleted; its processings and runs keep the department id but losedepartmentName; the UI labels it "Ancien département (id)" / "Former department (id)" (owner avatar tooltip through lib-vuetify 2.5.1, owner filters and activity throughuseDisplayOwnerfrom lib-vue 1.31.1 — the local composable is gone, feat(vue): useDisplayOwner and owner-avatar label a deleted department lib#52);relativeDependencieson lib for local developmentDELETE /processings/:id; the webhook left the directory behind), thelimitsdocument too; a deleted organization is pulled from the partner permissions of others;created/updatedonly keep the id of a former usercreated/updatedname is now optional in the processing schema; the UI shows "Ancien utilisateur" / "Former user" when it is absenttests/features/processings/identities.api.spec.ts: renames, end of a partnership, department rename and deletion, user deletion, organization deletion (directory and limits included)Why: GDPR and consistency — partner permissions ignored the end of a partnership, a deleted department kept showing under its old name, and a deleted owner left its processing directories on disk.
Heads-up:
userEmailpermissions are not touched: the webhook only carries the user id, so a former user's email survives there (tracked as a contract extension).