mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-20 11:37:51 +00:00
enhance: inherit team access for all units (#38938)
Admin and write team authorize now grant that mode on every unit, including units added later, instead of only rows present in `team_unit`. Granular teams keep `authorize=none` and explicit unit rows. Closes the `TEAM-UNIT-PERMISSION` design gap from https://github.com/go-gitea/gitea/pull/34128. Maybe also fix #15962 (actually maybe it had been fixed before, the root cause is out-of-sync "access" table) ## Screenshots only writing selected: <img width="1399" height="1007" alt="image" src="https://github.com/user-attachments/assets/1d1b4c49-a59a-47b6-998f-0464a067395b" /> _Created with the help of AI_ --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
@@ -10,11 +10,9 @@ import (
|
||||
|
||||
auth_model "gitea.dev/models/auth"
|
||||
repo_model "gitea.dev/models/repo"
|
||||
"gitea.dev/models/unit"
|
||||
"gitea.dev/models/unittest"
|
||||
user_model "gitea.dev/models/user"
|
||||
api "gitea.dev/modules/structs"
|
||||
"gitea.dev/modules/util"
|
||||
"gitea.dev/tests"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -38,13 +36,13 @@ func TestAPIRepoTeams(t *testing.T) {
|
||||
if assert.Len(t, teams, 2) {
|
||||
assert.Equal(t, "Owners", teams[0].Name)
|
||||
assert.True(t, teams[0].CanCreateOrgRepo)
|
||||
assert.True(t, util.SliceSortedEqual(unit.AllUnitKeyNames(), teams[0].Units), "%v == %v", unit.AllUnitKeyNames(), teams[0].Units)
|
||||
assert.Equal(t, []string{"repo.issues"}, teams[1].Units) // legacy dirty data, although the team.authorize is "owner", the units are also responded
|
||||
assert.Equal(t, api.AccessLevelNameOwner, teams[0].Permission)
|
||||
|
||||
assert.Equal(t, "test_team", teams[1].Name)
|
||||
assert.False(t, teams[1].CanCreateOrgRepo)
|
||||
assert.Equal(t, []string{"repo.issues"}, teams[1].Units)
|
||||
assert.Equal(t, api.AccessLevelNameWrite, teams[1].Permission)
|
||||
assert.Equal(t, api.AccessLevelNameWrite, teams[1].Permission) // legacy dirty data, although the team.authorize is "write", the units are also responded
|
||||
}
|
||||
|
||||
// IsTeam
|
||||
|
||||
Reference in New Issue
Block a user