Repository navigation
支持独立权限组、站点协议编辑与原生 Git 文档提交 - #4
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fd6267ffc8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| await store.persist(objects); | ||
| await recordHead(c.env.DB, current.id, lease, update.newOid, after.version, after.last_revision_id, user.id, commits); |
There was a problem hiding this comment.
Avoid rejecting pushes after publishing their Wiki revision
If an R2 write, recordHead, lease check, or the post-write concurrency check fails after the internal Wiki PUT succeeds, the catch block returns ng refs/heads/main even though the submitted content has already been published as a Wiki revision. The Git client therefore reports a failed push and may prompt the user to retry, while readers have already seen the supposedly rejected edit and the repository head still points elsewhere. Persist the validated objects before mutating the page and make the page-version/ref update atomic or compensate the Wiki mutation before reporting rejection.
Useful? React with 👍 / 👎.
| @@ -0,0 +1,11 @@ | |||
| export const EDITABLE_ROLES = ['user', 'discussion_manager', 'admin'] as const; | |||
| export const PERMISSION_KEYS = [ | |||
| 'wiki:create', 'wiki:edit', 'wiki:delete', 'wiki:restore', 'wiki:move', 'wiki:revert', 'git:push', | |||
There was a problem hiding this comment.
Apply the independent create permission to MCP tool exposure
Splitting wiki:create from wiki:edit is not reflected in MCP discovery: getBaseVisibleToolDefs in src/routes/mcp.ts:139-146 exposes all USER_TOOL_DEFS, including create_or_update_page, only when wiki:edit is granted. A role configured with create-only access therefore cannot discover or use the MCP creation workflow, while an edit-only role is still advertised a creation-capable tool whose eventual commit is rejected by the new wiki:create check. Gate the create-capable MCP tools using both independent permissions, or split their definitions by operation.
Useful? React with 👍 / 👎.
| if (page.deleted_at && (window.currentUser.permissions?.['wiki:restore'] || window.currentUser.role === 'super_admin')) { | ||
| moreActionsHtml += ui("m_36c060161233f9b5", [window.escapeHtml(actionSlug), window.escapeHtml(actionSlug)]); |
There was a problem hiding this comment.
Let restore grantees load deleted pages
For a user or discussion_manager granted the new wiki:restore permission, this restore action is unreachable: GET /api/w/:slug still returns 410 for every deleted page unless admin:access is present (src/routes/wiki.ts:1666-1671), and the 410 branch returns before this menu is rendered. The deleted-pages listing is also admin-only, so non-admin restore grantees have no normal UI path to invoke the permission. Allow wiki:restore holders to receive the deleted-page metadata needed to render this action, without exposing its content if that is meant to remain restricted.
Useful? React with 👍 / 👎.
| * 문서 이동 (이름 변경) — 관리자 전용. 핵심 로직은 공유 헬퍼 movePage 에 위임한다. | ||
| */ | ||
| wiki.post('/w/:slug/move', requireAdmin, async (c) => { | ||
| wiki.post('/w/:slug/move', requireAuth, requirePermission('wiki:move'), async (c) => { |
There was a problem hiding this comment.
Enforce the full page ACL before moving documents
Changing this route from admin-only to the independently assignable wiki:move permission lets non-admin grantees reach movePage, but its ACL check at src/routes/wiki.ts:3454-3461 rejects only admin_only. A user who does not satisfy an aged, page_editor, or any_editor restriction can therefore rename that protected page and optionally initiate backlink rewrites, even though delete and revert evaluate the same ACL rules before mutating a page. Run evaluateEditAcl for non-admin moves rather than checking only one flag.
Useful? React with 👍 / 👎.
新增最高管理员权限矩阵,独立配置三类用户的 17 项操作权限,并在网页、MCP 和后台写入路径执行。增加服务条款/隐私政策后台 Markdown 编辑、初始模板和页脚入口。
每篇文档提供 HTTPS smart HTTP Git 仓库,支持标准 clone/pull/push。30 天 Git 专用令牌可撤销,所有推送共用 Wiki ACL、审批及版本冲突校验。只允许 main 的线性快进,所有用户均不能覆盖历史、删除引用、创建分支、提交标签或合并节点。私有文档和隐藏修订在 Git 下载时同样受限。第一版的历史与大小限制、批量推送对应单条 Wiki 修订等说明见 GIT_EDITING.md。
修复站点自定义名称导致静态页面标题漏翻译的问题。
验证:服务端/客户端类型检查;6 项权限测试;3 项 Git 测试(真实 Git CLI 覆盖 clone、批量 push、web pull、force/delete 拒绝、ACL、权限撤销、私有访问、隐藏历史及恶意 pack 大小);10 项 i18n/42 个构建页面检查;完整构建;Wrangler dry-run(gzip 492 KiB)。