Split employee devices from DeviceConnection

viewer.enrolledDevices shared DeviceConnection with the admin
org list, so totalCount had to authorize with both
employee-device:list and device:list. Mirror
EmployeeDocumentConnection: a dedicated EmployeeDeviceConnection
without totalCount, and keep DeviceConnection.totalCount for
the org fleet only. Cover assumed-session device:get IDOR in e2e.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-21 15:06:12 +02:00
parent 85864a580c
commit 6cac6a8775
7 changed files with 67 additions and 27 deletions

View File

@@ -119,6 +119,22 @@ type DeviceEdge {
node: Device!
}
type EmployeeDeviceConnection
@goModel(
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.EmployeeDeviceConnection"
) {
edges: [EmployeeDeviceEdge!]!
pageInfo: PageInfo!
}
type EmployeeDeviceEdge
@goModel(
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.EmployeeDeviceEdge"
) {
cursor: CursorKey!
node: Device!
}
type CreateDevicePayload {
device: Device!
# enrollmentToken is shown ONCE; exchange via agent REST /enroll.

View File

@@ -30,7 +30,7 @@ type Viewer {
last: Int
before: CursorKey
orderBy: DeviceOrder
): DeviceConnection! @goField(forceResolver: true)
): EmployeeDeviceConnection! @goField(forceResolver: true)
# Own-device read for self-enrollment status polling before org assumption.
enrolledDevice(id: ID!): Device @goField(forceResolver: true)