mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 02:43:44 +00:00
What someone may do on the dashboard is now their GM level's permissions plus the grants on their account, minus its denies (PermissionGrants.h). A deny beats a grant; denies never apply to GM 9, and settings and permissions_manage stay GM 9 only. The account's grants are read with every request (like its GM level), so a change applies at once, and they are passed through every check: RouteUtils::Can, CanViewCharacter, the rank rules (self_* and manage_equal_rank), routes guarded by a permission, the templates' `can`, the API documentation, API access, API key scopes (a key never does more than its owner may now) and WebSocket subscriptions. New permission grants_manage (GM 9 by default) and the API to manage grants: GET /api/grants/catalog, GET /api/grants, POST /api/grants, POST /api/grants/:id/remove. Nobody grants or takes away what they don't hold themselves (a permission, every permission of a group, a command they may use, every command up to their own GM level), and only on accounts the rank rules let them manage (their own with self_moderation). Commands with a fixed level or a floor above GM 1 (/execute) can't be granted. Every change goes in the audit log (grant_permission, deny_permission, remove_grant). Also: the Showcase gate and the traffic subscription now check their permission by name. Check: grant a GM 2 account accounts_ban (it can ban, and the Ban button shows); deny a GM 8 account accounts_view (the accounts list is refused); give an expiry a minute ahead and see it stop; try to grant a permission your account doesn't have (refused); dWebTests PermissionGrantsTests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
95 lines
2.3 KiB
CMake
95 lines
2.3 KiB
CMake
set(DCOMMON_SOURCES
|
|
"AMFDeserialize.cpp"
|
|
"AmfSerialize.cpp"
|
|
"BinaryIO.cpp"
|
|
"dConfig.cpp"
|
|
"Diagnostics.cpp"
|
|
"TrafficStats.cpp"
|
|
"Locale.cpp"
|
|
"Logger.cpp"
|
|
"Game.cpp"
|
|
"GeneralUtils.cpp"
|
|
"LDFFormat.cpp"
|
|
"Metrics.cpp"
|
|
"NiPoint3.cpp"
|
|
"NiQuaternion.cpp"
|
|
"Demangler.cpp"
|
|
"ZCompression.cpp"
|
|
"BrickByBrickFix.cpp"
|
|
"BinaryPathFinder.cpp"
|
|
"FdbToSqlite.cpp"
|
|
"JSONUtils.cpp"
|
|
"TinyXmlUtils.cpp"
|
|
"Sd0.cpp"
|
|
"Lxfml.cpp"
|
|
"LxfmlBugged.cpp"
|
|
"VanityXml.cpp"
|
|
"ScheduleRules.cpp"
|
|
"EventParts.cpp"
|
|
"VanityEvents.cpp"
|
|
"ZoneFile.cpp"
|
|
"LevelFile.cpp"
|
|
"Raw.cpp"
|
|
"ZoneScenes.cpp"
|
|
"Process.cpp"
|
|
"Permissions.cpp"
|
|
"PermissionGrants.cpp"
|
|
"NifFile.cpp"
|
|
)
|
|
|
|
# Workaround for compiler bug where the optimized code could result in a memcpy of 0 bytes, even though that isnt possible.
|
|
# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=97185
|
|
if (CMAKE_CXX_COMPILER_ID STREQUAL "GNU")
|
|
set_source_files_properties("FdbToSqlite.cpp" PROPERTIES COMPILE_FLAGS "-Wno-stringop-overflow")
|
|
endif()
|
|
|
|
add_subdirectory(dClient)
|
|
|
|
foreach(file ${DCOMMON_DCLIENT_SOURCES})
|
|
set(DCOMMON_SOURCES ${DCOMMON_SOURCES} "dClient/${file}")
|
|
endforeach()
|
|
|
|
add_library(dCommon STATIC ${DCOMMON_SOURCES})
|
|
target_include_directories(dCommon
|
|
PUBLIC "." "dClient" "dEnums"
|
|
PRIVATE
|
|
"${PROJECT_SOURCE_DIR}/dDatabase/GameDatabase"
|
|
"${PROJECT_SOURCE_DIR}/dDatabase/GameDatabase/ITables"
|
|
"${PROJECT_SOURCE_DIR}/dDatabase/CDClientDatabase"
|
|
)
|
|
|
|
if (UNIX)
|
|
find_package(ZLIB REQUIRED)
|
|
elseif (WIN32)
|
|
include(FetchContent)
|
|
|
|
FetchContent_Declare(
|
|
zlib
|
|
URL https://github.com/madler/zlib/archive/refs/tags/v1.3.2.zip
|
|
URL_HASH MD5=adbba6eef8960c3412818b2e241f46dc
|
|
GIT_PROGRESS TRUE
|
|
GIT_SHALLOW 1
|
|
)
|
|
|
|
# Disable warning about no project version.
|
|
set(CMAKE_POLICY_DEFAULT_CMP0048 NEW)
|
|
# Disable warning about the minimum version of cmake used for bcrypt being deprecated in the future
|
|
set(CMAKE_WARN_DEPRECATED OFF CACHE BOOL "" FORCE)
|
|
# Disable zlib tests
|
|
set(ZLIB_BUILD_TESTING OFF CACHE BOOL "" FORCE)
|
|
|
|
FetchContent_MakeAvailable(zlib)
|
|
|
|
set(ZLIB_INCLUDE_DIRS ${zlib_SOURCE_DIR} ${zlib_BINARY_DIR})
|
|
else ()
|
|
message(
|
|
FATAL_ERROR
|
|
"This platform does not have a way to use zlib.\nCreate an issue on GitHub with your build system so it can be configured."
|
|
)
|
|
endif ()
|
|
|
|
target_link_libraries(dCommon
|
|
PUBLIC glm::glm
|
|
PRIVATE ZLIB::ZLIB bcrypt tinyxml2
|
|
INTERFACE dDatabase)
|