1
0
Fork 0

feat(projects): enforce permissions and improve search

This commit is contained in:
Jason Fraley 2026-08-21 00:26:33 -04:00
parent 282ca9eddf
commit 6d58451978
9 changed files with 115 additions and 15 deletions

View file

@ -3,6 +3,7 @@ import { headers as nextHeaders } from "next/headers";
import { notFound, redirect } from "next/navigation";
import { getPayload } from "payload";
import { ProjectBoardView } from "@/components/frontend/projects/ProjectBoardView";
import { hasPermission } from "@/utils/access-control/hasPermission";
export const metadata = {
title: "Board — Polaris Task Force",
@ -10,10 +11,14 @@ export const metadata = {
const KANBAN_STATUSES = [
{ status: "open", label: "Open" },
{ status: "planning", label: "Planning" },
{ status: "in_progress", label: "In Progress" },
{ status: "in_review", label: "In Review" },
{ status: "waiting_on_reporter", label: "Waiting on Reporter" },
{ status: "in_testing", label: "Testing" },
{ status: "resolved", label: "Done" },
{ status: "canceled", label: "Canceled" },
{ status: "closed", label: "Closed" },
] as const;
export default async function BoardPage({
@ -43,6 +48,7 @@ export default async function BoardPage({
}
const project = projectResult.docs[0] as any;
const canManageTickets = await hasPermission(payload, user, "tickets:staff");
const [ticketResult, sprintResult, labelResult] = await Promise.all([
payload.find({
@ -147,7 +153,7 @@ export default async function BoardPage({
project: l.project,
}))}
currentUserId={user.id as number}
isAdmin={true}
isAdmin={canManageTickets}
/>
</div>
);

View file

@ -3,6 +3,8 @@ import { headers as nextHeaders } from "next/headers";
import { notFound, redirect } from "next/navigation";
import { getPayload } from "payload";
import { ReleasesView } from "@/components/frontend/projects/ReleasesView";
import { hasPermission } from "@/utils/access-control/hasPermission";
import { richTextToPlaintext } from "@/lib/projects/projectMeta";
export const metadata = {
title: "Releases — Polaris Task Force",
@ -35,6 +37,8 @@ export default async function ReleasesPage({
}
const project = projectResult.docs[0] as any;
const canManage = await hasPermission(payload, user, "releases:update");
const canCreate = await hasPermission(payload, user, "releases:create");
const [releaseResult, ticketResult] = await Promise.all([
payload.find({
@ -75,7 +79,7 @@ export default async function ReleasesPage({
status: r.status,
targetVersion: r.targetVersion,
releaseDate: r.releaseDate,
description: r.description,
description: richTextToPlaintext(r.description) || null,
createdAt: r.createdAt,
ticketsTotal,
ticketsResolved,
@ -91,7 +95,7 @@ export default async function ReleasesPage({
key: project.key,
}}
releases={releases}
isAdmin={true}
isAdmin={canManage || canCreate}
/>
</div>
);

View file

@ -3,6 +3,7 @@ import { headers as nextHeaders } from "next/headers";
import { notFound, redirect } from "next/navigation";
import { getPayload } from "payload";
import { SprintsView } from "@/components/frontend/projects/SprintsView";
import { hasPermission } from "@/utils/access-control/hasPermission";
export const metadata = {
title: "Sprints — Polaris Task Force",
@ -35,6 +36,8 @@ export default async function SprintsPage({
}
const project = projectResult.docs[0] as any;
const canManage = await hasPermission(payload, user, "sprints:update");
const canCreate = await hasPermission(payload, user, "sprints:create");
const [sprintResult, ticketResult] = await Promise.all([
payload.find({
@ -97,7 +100,7 @@ export default async function SprintsPage({
key: project.key,
}}
sprints={sprints}
isAdmin={true}
isAdmin={canManage || canCreate}
/>
</div>
);

View file

@ -23,6 +23,16 @@ async function authenticate() {
return { payload, user };
}
async function requirePermission(
payload: Awaited<ReturnType<typeof getPayload>>,
user: Parameters<typeof hasPermission>[1],
permission: Parameters<typeof hasPermission>[2],
) {
if (!(await hasPermission(payload, user, permission))) {
throw new Error("You don't have permission to manage project tracking.");
}
}
export async function createProject(input: {
name: string;
key: string;
@ -31,6 +41,7 @@ export async function createProject(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "projects:create");
const name = input.name.trim();
if (!name) throw new Error("Project name is required.");
@ -93,6 +104,7 @@ export async function createSprint(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "sprints:create");
const name = input.name.trim();
if (!name) throw new Error("Sprint name is required.");
@ -132,6 +144,7 @@ export async function startSprint(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "sprints:update");
const sprint = await payload.update({
collection: "sprints" as any,
@ -161,6 +174,7 @@ export async function completeSprint(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "sprints:update");
const sprint = await payload.update({
collection: "sprints" as any,
@ -190,6 +204,7 @@ export async function startRelease(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "releases:update");
const release = await payload.update({
collection: "releases" as any,
@ -219,6 +234,7 @@ export async function completeRelease(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "releases:update");
const release = await payload.update({
collection: "releases" as any,
@ -252,6 +268,7 @@ export async function createRelease(input: {
}): Promise<ActionResult> {
try {
const { payload, user } = await authenticate();
await requirePermission(payload, user, "releases:create");
const name = input.name.trim();
if (!name) throw new Error("Release name is required.");

View file

@ -3,6 +3,8 @@ import { headers as nextHeaders } from "next/headers";
import { redirect } from "next/navigation";
import { getPayload } from "payload";
import { ProjectsView } from "@/components/frontend/projects/ProjectsView";
import { hasPermission } from "@/utils/access-control/hasPermission";
import { richTextToPlaintext } from "@/lib/projects/projectMeta";
export const metadata = {
title: "Projects — Polaris Task Force",
@ -24,6 +26,7 @@ export default async function ProjectsPage() {
limit: 100,
overrideAccess: true,
});
const canCreate = await hasPermission(payload, user, "projects:create");
return (
<div className="flex flex-col gap-6 p-5">
@ -40,12 +43,12 @@ export default async function ProjectsPage() {
p.lead.payloadDisplayName || p.lead.username,
}
: null,
description: p.description,
description: richTextToPlaintext(p.description) || null,
createdAt: p.createdAt,
updatedAt: p.updatedAt,
}))}
currentUserId={user.id as number}
isAdmin={true}
isAdmin={canCreate}
/>
</div>
);

View file

@ -22,7 +22,7 @@ export default async function SearchPage() {
collection: "tickets" as any,
where: { project: { exists: true } },
depth: 2,
limit: 500,
pagination: false,
overrideAccess: true,
}),
payload.find({
@ -39,6 +39,7 @@ export default async function SearchPage() {
status: t.status,
priority: t.priority,
type: t.type || "task",
category: t.category,
storyPoints: t.storyPoints,
project: t.project
? typeof t.project === "object"
@ -55,6 +56,7 @@ export default async function SearchPage() {
? { id: t.assignee.id, displayName: t.assignee.payloadDisplayName || t.assignee.username }
: { id: t.assignee, displayName: `User #${t.assignee}` }
: null,
href: `/helpdesk/${t.id}`,
}));
const labels = (labelResult.docs as any[]).map((l) => ({

View file

@ -11,7 +11,10 @@ export const Projects: CollectionConfig = {
},
access: {
read: ({ req }) => !!req.user,
create: ({ req }) => !!req.user,
create: async ({ req }) => {
if (!req.user) return false;
return await hasPermission(req.payload, req.user, "projects:create");
},
update: async ({ req }) => {
if (!req.user) return false;
return await hasPermission(req.payload, req.user, "projects:update");

View file

@ -13,6 +13,13 @@ import {
ItemTitle,
} from "@/components/ui/item";
import { cn } from "@/lib/utils";
import {
Select,
SelectContent,
SelectItem,
SelectTrigger,
SelectValue,
} from "@/components/ui/select";
export interface SearchTicket {
readonly id: number;
@ -20,10 +27,12 @@ export interface SearchTicket {
readonly status: string;
readonly priority: string;
readonly type: string;
readonly category?: string;
readonly storyPoints?: number | null;
readonly project: { readonly id: number; readonly name: string; readonly key: string };
readonly labels: readonly { id: number; name: string; color: string }[];
readonly assignee: { id: number; displayName: string } | null;
readonly href: string;
}
export interface LabelOption {
@ -61,6 +70,8 @@ function labelFor(value: string): string {
export function ProjectSearchView({ tickets, allLabels }: ProjectSearchViewProps) {
const [search, setSearch] = useState("");
const [selectedLabelIds, setSelectedLabelIds] = useState<readonly number[]>([]);
const [status, setStatus] = useState("all");
const [type, setType] = useState("all");
function toggleLabel(labelId: number) {
setSelectedLabelIds((current) =>
@ -73,17 +84,19 @@ export function ProjectSearchView({ tickets, allLabels }: ProjectSearchViewProps
const filteredTickets = useMemo(() => {
return tickets.filter((ticket) => {
const matchesSearch = !query
|| ticket.title.toLowerCase().includes(query)
|| ticket.project.name.toLowerCase().includes(query)
|| ticket.project.key.toLowerCase().includes(query);
|| `${ticket.id} ${ticket.title} ${ticket.status} ${ticket.priority} ${ticket.type} ${ticket.category ?? ""} ${ticket.project.name} ${ticket.project.key} ${ticket.labels.map((label) => label.name).join(" ")}`
.toLowerCase()
.includes(query);
const matchesLabels =
selectedLabelIds.length === 0
|| ticket.labels.some((label) => selectedLabelIds.includes(label.id));
const matchesStatus = status === "all" || ticket.status === status;
const matchesType = type === "all" || ticket.type === type;
return matchesSearch && matchesLabels;
return matchesSearch && matchesLabels && matchesStatus && matchesType;
});
}, [tickets, query, selectedLabelIds]);
}, [tickets, query, selectedLabelIds, status, type]);
const groupedByProject = useMemo(() => {
const groups = new Map<string, { project: SearchTicket["project"]; tickets: SearchTicket[] }>();
@ -122,6 +135,39 @@ export function ProjectSearchView({ tickets, allLabels }: ProjectSearchViewProps
/>
</div>
<div className="flex flex-wrap gap-2">
<Select value={status} onValueChange={setStatus}>
<SelectTrigger className="w-[160px]" aria-label="Filter by status">
<SelectValue placeholder="All statuses" />
</SelectTrigger>
<SelectContent>
<SelectItem value="all">All statuses</SelectItem>
<SelectItem value="open">Open</SelectItem>
<SelectItem value="planning">Planning</SelectItem>
<SelectItem value="in_progress">In progress</SelectItem>
<SelectItem value="in_review">In review</SelectItem>
<SelectItem value="waiting_on_reporter">Waiting on reporter</SelectItem>
<SelectItem value="in_testing">Testing</SelectItem>
<SelectItem value="resolved">Resolved</SelectItem>
<SelectItem value="canceled">Canceled</SelectItem>
<SelectItem value="closed">Closed</SelectItem>
</SelectContent>
</Select>
<Select value={type} onValueChange={setType}>
<SelectTrigger className="w-[150px]" aria-label="Filter by issue type">
<SelectValue placeholder="All types" />
</SelectTrigger>
<SelectContent>
<SelectItem value="all">All types</SelectItem>
<SelectItem value="task">Task</SelectItem>
<SelectItem value="bug">Bug</SelectItem>
<SelectItem value="story">Story</SelectItem>
<SelectItem value="epic">Epic</SelectItem>
<SelectItem value="improvement">Improvement</SelectItem>
</SelectContent>
</Select>
</div>
{allLabels.length > 0 && (
<div className="flex flex-wrap items-center gap-2">
<BadgeIcon className="size-3 text-muted-foreground" />
@ -177,7 +223,8 @@ export function ProjectSearchView({ tickets, allLabels }: ProjectSearchViewProps
<div className="flex flex-col gap-1 pl-4" role="list">
{projectTickets.map((ticket) => (
<Item key={ticket.id} variant="outline" size="sm" role="listitem">
<Link href={ticket.href} key={ticket.id} className="block rounded-md">
<Item variant="outline" size="sm" role="listitem" className="transition-colors hover:bg-accent/50">
<ItemHeader className="items-center">
<div className="flex min-w-0 items-center gap-2">
<ItemTitle className="truncate text-sm font-medium">{ticket.title}</ItemTitle>
@ -220,7 +267,8 @@ export function ProjectSearchView({ tickets, allLabels }: ProjectSearchViewProps
</div>
)}
</ItemContent>
</Item>
</Item>
</Link>
))}
</div>
</div>

View file

@ -19,3 +19,17 @@ export const TYPE_STYLES: Readonly<Record<string, string>> = {
improvement: "bg-amber-500/15 text-amber-400 border-amber-500/30",
subtask: "bg-sky-500/15 text-sky-400 border-sky-500/30",
};
/** Safely extracts readable text from Payload's Lexical rich-text JSON. */
export function richTextToPlaintext(value: unknown): string {
if (typeof value === "string") return value;
if (!value || typeof value !== "object") return "";
const node = value as { text?: unknown; children?: unknown };
if (typeof node.text === "string") return node.text;
if (!Array.isArray(node.children)) return "";
return node.children
.map((child) => richTextToPlaintext(child))
.filter(Boolean)
.join(" ");
}