mirror of
https://github.com/directus/directus.git
synced 2026-04-25 03:00:53 -04:00
* Step 1 * Step 2 * False sense of confidence * Couple more before dinner * Update schema package * Update format-title * Upgrade specs file * Close * Replace ts-node-dev with tsx, and various others * Replace lodash with lodash-es * Add lodash-es types * Update knex import * More fun is had * FSE * Consolidate repos * Various tweaks and fixes * Fix specs * Remove dependency on knex-schema-inspector * Fix wrong imports of inspector * Move shared exceptions to new package * Move constants to separate module * Move types to new types package * Use directus/types * I believe this is no longer needed * [WIP] Start moving utils to esm * ESMify Shared * Move shared utils to @directus/utils * Use @directus/utils instead of @directus/shared/utils * It runs! * Use correct schemaoverview type * Fix imports * Fix the thing * Start on new update-checker lib * Use new update-check package * Swap out directus/shared in app * Pushing through the last bits now * Dangerously make extensions SDK ESM * Use @directus/types in tests * Copy util function to test * Fix linter config * Add missing import * Hot takes * Fix build * Curse these default exports * No tests in constants * Add tests * Remove tests from types * Add tests for exceptions * Fix test * Fix app tests * Fix import in test * Fix various tests * Fix specs export * Some more tests * Remove broken integration tests These were broken beyond repair.. They were also written before we really knew what we we're doing with tests, so I think it's better to say goodbye and start over with these * Regenerate lockfile * Fix imports from merge * I create my own problems * Make sharp play nice * Add vitest config * Install missing blackbox dep * Consts shouldn't be in types tsk tsk tsk tsk * Fix type/const usage in extensions-sdk * cursed.default * Reduce circular deps * Fix circular dep in items service * vvv * Trigger testing for all vendors * Add workaround for rollup * Prepend the file protocol for the ESM loader to be compatible with Windows "WARN: Only URLs with a scheme in: file and data are supported by the default ESM loader. On Windows, absolute paths must be valid file:// URLs. Received protocol 'c:'" * Fix postgres * Schema package updates Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com> * Resolve cjs/mjs extensions * Clean-up eslint config * fixed extension concatination * using string interpolation for consistency * Revert MySQL optimisation * Revert testing for all vendors * Replace tsx with esbuild-kit/esm-loader Is a bit faster and we can rely on the built-in `watch` and `inspect` functionalities of Node.js Note: The possibility to watch other files (.env in our case) might be added in the future, see https://github.com/nodejs/node/issues/45467 * Use exact version for esbuild-kit/esm-loader * Fix import --------- Co-authored-by: ian <licitdev@gmail.com> Co-authored-by: Brainslug <tim@brainslug.nl> Co-authored-by: Azri Kahar <42867097+azrikahar@users.noreply.github.com> Co-authored-by: Pascal Jufer <pascal-jufer@bluewin.ch>
126 lines
3.6 KiB
TypeScript
126 lines
3.6 KiB
TypeScript
import type { Permission, PermissionsAction, SchemaOverview } from '@directus/types';
|
|
import { uniq } from 'lodash-es';
|
|
|
|
/**
|
|
* Reduces the schema based on the included permissions. The resulting object is the schema structure, but with only
|
|
* the allowed collections/fields/relations included based on the permissions.
|
|
* @param schema The full project schema
|
|
* @param actions Array of permissions actions (crud)
|
|
* @returns Reduced schema
|
|
*/
|
|
export function reduceSchema(
|
|
schema: SchemaOverview,
|
|
permissions: Permission[] | null,
|
|
actions: PermissionsAction[] = ['create', 'read', 'update', 'delete']
|
|
): SchemaOverview {
|
|
const reduced: SchemaOverview = {
|
|
collections: {},
|
|
relations: [],
|
|
};
|
|
|
|
const allowedFieldsInCollection =
|
|
permissions
|
|
?.filter((permission) => actions.includes(permission.action))
|
|
.reduce((acc, permission) => {
|
|
if (!acc[permission.collection]) {
|
|
acc[permission.collection] = [];
|
|
}
|
|
|
|
if (permission.fields) {
|
|
acc[permission.collection] = uniq([...acc[permission.collection]!, ...permission.fields]);
|
|
}
|
|
|
|
return acc;
|
|
}, {} as { [collection: string]: string[] }) ?? {};
|
|
|
|
for (const [collectionName, collection] of Object.entries(schema.collections)) {
|
|
if (
|
|
!permissions?.some(
|
|
(permission) => permission.collection === collectionName && actions.includes(permission.action)
|
|
)
|
|
) {
|
|
continue;
|
|
}
|
|
|
|
const fields: SchemaOverview['collections'][string]['fields'] = {};
|
|
|
|
for (const [fieldName, field] of Object.entries(schema.collections[collectionName]!.fields)) {
|
|
if (
|
|
!allowedFieldsInCollection[collectionName]?.includes('*') &&
|
|
!allowedFieldsInCollection[collectionName]?.includes(fieldName)
|
|
) {
|
|
continue;
|
|
}
|
|
|
|
const o2mRelation = schema.relations.find(
|
|
(relation) => relation.related_collection === collectionName && relation.meta?.one_field === fieldName
|
|
);
|
|
|
|
if (
|
|
o2mRelation &&
|
|
!permissions?.some(
|
|
(permission) => permission.collection === o2mRelation.collection && actions.includes(permission.action)
|
|
)
|
|
) {
|
|
continue;
|
|
}
|
|
|
|
fields[fieldName] = field;
|
|
}
|
|
|
|
reduced.collections[collectionName] = {
|
|
...collection,
|
|
fields,
|
|
};
|
|
}
|
|
|
|
reduced.relations = schema.relations.filter((relation) => {
|
|
let collectionsAllowed = true;
|
|
let fieldsAllowed = true;
|
|
|
|
if (Object.keys(allowedFieldsInCollection).includes(relation.collection) === false) {
|
|
collectionsAllowed = false;
|
|
}
|
|
|
|
if (
|
|
relation.related_collection &&
|
|
(Object.keys(allowedFieldsInCollection).includes(relation.related_collection) === false ||
|
|
// Ignore legacy permissions with an empty fields array
|
|
allowedFieldsInCollection[relation.related_collection]?.length === 0)
|
|
) {
|
|
collectionsAllowed = false;
|
|
}
|
|
|
|
if (
|
|
relation.meta?.one_allowed_collections &&
|
|
relation.meta.one_allowed_collections.every((collection) =>
|
|
Object.keys(allowedFieldsInCollection).includes(collection)
|
|
) === false
|
|
) {
|
|
collectionsAllowed = false;
|
|
}
|
|
|
|
if (
|
|
!allowedFieldsInCollection[relation.collection] ||
|
|
(allowedFieldsInCollection[relation.collection]?.includes('*') === false &&
|
|
allowedFieldsInCollection[relation.collection]?.includes(relation.field) === false)
|
|
) {
|
|
fieldsAllowed = false;
|
|
}
|
|
|
|
if (
|
|
relation.related_collection &&
|
|
relation.meta?.one_field &&
|
|
(!allowedFieldsInCollection[relation.related_collection] ||
|
|
(allowedFieldsInCollection[relation.related_collection]?.includes('*') === false &&
|
|
allowedFieldsInCollection[relation.related_collection]?.includes(relation.meta?.one_field) === false))
|
|
) {
|
|
fieldsAllowed = false;
|
|
}
|
|
|
|
return collectionsAllowed && fieldsAllowed;
|
|
});
|
|
|
|
return reduced;
|
|
}
|