refactor(discord): einheitliche Berechtigung über verknüpfte Konten
Nutzerfrage: warum gibt es neben der Kontoverknüpfung noch eine separate "Erlaubte Nutzer-IDs"-Liste, und woher weiß der Bot, ob jemand Kunde oder Personal ist? Antwort: das waren zwei parallele, verwirrende Mechanismen. /kc-status und /kc-kunde prüften bisher eine manuell gepflegte Discord-ID-Liste (aus der Zeit vor der OAuth- Verknüpfung), während /zuweisen und /schliessen bereits das verknüpfte Personal-Konto (users.discord_user_id, kind='staff') prüften. Jetzt einheitlich: alle vier Personal-Befehle verlangen ein verknüpftes Personal-Konto, genau wie /zuweisen und /schliessen. Die Liste entfällt vollständig (Migration 029, Spalte staff_user_ids entfernt) – wer ein Personal-Konto im Kundencenter hat und es unter "Mein Konto" mit Discord verknüpft, darf automatisch alle vier Befehle nutzen, ohne zusätzliche manuelle Pflege einer ID-Liste. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
8243cdb111
commit
078b1357fb
4 changed files with 20 additions and 20 deletions
|
|
@ -11,7 +11,6 @@ import type { KcModule } from '../../core/module.js';
|
|||
const ID = /^\d{15,25}$/; // Discord-Snowflake-IDs
|
||||
const settingsView = (s: any) => ({
|
||||
enabled: !!s.enabled, hasToken: !!s.token_enc, guildId: s.guild_id, adminChannelId: s.admin_channel_id,
|
||||
staffUserIds: String(s.staff_user_ids ?? '').split(',').map((x: string) => x.trim()).filter(Boolean),
|
||||
clientId: s.client_id, hasClientSecret: !!s.client_secret_enc, ticketChannelId: s.ticket_channel_id,
|
||||
configured: !!s.token_enc, lastConnectedAt: s.last_connected_at, lastError: s.last_error, updatedAt: s.updated_at,
|
||||
});
|
||||
|
|
@ -31,11 +30,11 @@ export const discordModule: KcModule = {
|
|||
token: z.string().max(200).nullable().optional(), // undefined = unverändert lassen, null = löschen
|
||||
guildId: z.string().trim().regex(ID).nullable(), adminChannelId: z.string().trim().regex(ID).nullable(),
|
||||
ticketChannelId: z.string().trim().regex(ID).nullable(),
|
||||
staffUserIds: z.array(z.string().trim().regex(ID)).max(50), enabled: z.boolean().default(false),
|
||||
enabled: z.boolean().default(false),
|
||||
clientId: z.string().trim().regex(ID).nullable(), clientSecret: z.string().max(200).nullable().optional(),
|
||||
}).parse(req.body);
|
||||
const sets = ['guild_id = ?', 'admin_channel_id = ?', 'ticket_channel_id = ?', 'staff_user_ids = ?', 'enabled = ?', 'client_id = ?', 'updated_by = ?'];
|
||||
const params: unknown[] = [b.guildId, b.adminChannelId, b.ticketChannelId, b.staffUserIds.join(','), b.enabled ? 1 : 0, b.clientId, a.user.id];
|
||||
const sets = ['guild_id = ?', 'admin_channel_id = ?', 'ticket_channel_id = ?', 'enabled = ?', 'client_id = ?', 'updated_by = ?'];
|
||||
const params: unknown[] = [b.guildId, b.adminChannelId, b.ticketChannelId, b.enabled ? 1 : 0, b.clientId, a.user.id];
|
||||
if (b.token !== undefined) { sets.push('token_enc = ?'); params.push(b.token ? encrypt(JSON.stringify({ token: b.token })) : null); }
|
||||
if (b.clientSecret !== undefined) { sets.push('client_secret_enc = ?'); params.push(b.clientSecret ? encrypt(JSON.stringify({ secret: b.clientSecret })) : null); }
|
||||
await run(`UPDATE discord_settings SET ${sets.join(', ')} WHERE id = 1`, params);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue