fix(backend): update protected app perm implicator

The permission implicator for protected apps was written before changes
to the permission system that affect the conditions under which a user
is allowed to grant and revoke permissions; specifically this is the
`manage:` set of permissions, which now needs to be granted to the owner
of a protected app.

Additionally, the "level" component of the permission is ignored because
the owner of a protected all is implied to have all the permissions
pertaining to that protected app.
This commit is contained in:
KernelDeimos
2026-01-20 16:07:10 -05:00
committed by Eric Dubé
parent 6805c90252
commit 79fda7b8c2
@@ -59,7 +59,7 @@ class ProtectedAppService extends BaseService {
// Owner of procted app has implicit permission to access it
svc_permission.register_implicator(PermissionImplicator.create({
matcher: permission => {
return permission.startsWith('app:');
return permission.startsWith('app:') || permission.startsWith('manage:app');
},
checker: async ({ actor, permission }) => {
if ( ! (actor.type instanceof UserActorType) ) {
@@ -67,10 +67,12 @@ class ProtectedAppService extends BaseService {
}
const parts = PermissionUtil.split(permission);
if ( parts.length !== 3 ) return undefined;
const [_, uid_part, lvl] = parts;
if ( lvl !== 'access' ) return undefined;
if ( parts[0] === 'manage' ) parts.shift();
if ( parts.length < 2 ) return undefined;
const [_, uid_part] = parts;
// track: slice a prefix
const uid = uid_part.slice('uid#'.length);