Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
-- Backfill the 4 default system roles on projects that have none.
Comment thread
StephaneTrebel marked this conversation as resolved.
-- Mirrors generateProjectCreateInput (apps/server-nestjs/src/modules/project/project.utils.ts):
-- Administrateur = MANAGE = 2
-- DevOps = MANAGE_ENVIRONMENTS | MANAGE_REPOSITORIES | REPLAY_HOOKS
-- | SEE_SECRETS | LIST_ENVIRONMENTS | LIST_REPOSITORIES = 984
-- Développeur = MANAGE_REPOSITORIES | LIST_ENVIRONMENTS | LIST_REPOSITORIES = 784
-- Lecture seule = LIST_ENVIRONMENTS | LIST_REPOSITORIES = 768
INSERT INTO "ProjectRole" ("id", "name", "permissions", "position", "oidcGroup", "type", "projectId")
SELECT
gen_random_uuid(),
r."name",
r."permissions",
r."position",
'/' || p."slug" || r."groupSuffix",
'system:managed',
p."id"
FROM "Project" p
CROSS JOIN (VALUES
('Administrateur', 2::bigint, 0, '/console/admin'),
('DevOps', 984::bigint, 1, '/console/devops'),
('Développeur', 784::bigint, 2, '/console/developer'),
('Lecture seule', 768::bigint, 3, '/console/readonly')
) AS r("name", "permissions", "position", "groupSuffix")
WHERE NOT EXISTS (
SELECT 1 FROM "ProjectRole" existing WHERE existing."projectId" = p."id"
);
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
-- Backfill the project system role 'Sécurité' on existing projects.
-- Mirrors the TS seeding in project.utils.ts (generateProjectCreateInput):
-- permissions 832 = SEE_SECRETS(64) | LIST_ENVIRONMENTS(256) | LIST_REPOSITORIES(512)
-- position 4 (after Lecture seule), oidcGroup = '/<project.slug>/console/security'
-- Anti-join on slug+position makes the INSERT idempotent: a retry after a
-- partial failure, or a project that already has the role, is a no-op.

INSERT INTO "ProjectRole" ("id", "name", "permissions", "projectId", "position", "oidcGroup", "type")
SELECT
gen_random_uuid(),
'Sécurité',
832, -- SEE_SECRETS(64) | LIST_ENVIRONMENTS(256) | LIST_REPOSITORIES(512)
p."id",
4,
'/' || p."slug" || '/console/security',
'system:managed'
FROM "Project" p
WHERE NOT EXISTS (
SELECT 1
FROM "ProjectRole" r
WHERE r."projectId" = p."id"
AND r."position" = 4
AND r."oidcGroup" = '/' || p."slug" || '/console/security'
);
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
INSERT INTO "AdminRole" ("id", "name", "permissions", "position", "oidcGroup", "type")
SELECT
'487450e6-3265-4df2-8581-8e39b0cecc5d'::uuid,
'Sécurité Plateforme',
1,
3,
'/console/security',
'system:managed'
WHERE NOT EXISTS (
SELECT 1 FROM "AdminRole"
WHERE "oidcGroup" = '/console/security'
OR "id" = '487450e6-3265-4df2-8581-8e39b0cecc5d'::uuid
);
Loading