Add invitingOrganizations field on viewer
Expose viewer.invitingOrganizations: [Organization!]! returning the organizations that have a live pending invitation directed at the current identity (accepted_at IS NULL AND expires_at > NOW()). The list is rendered under a "Pending invitations" section on the memberships page and in the organization selector dropdown, so a user already signed in with an existing identity can see which organizations have invited them without having to dig through their inbox. The new field is gated by iam:invitation:list against the viewer's own identity, so it does not loosen authorization on Organization elsewhere. E2E coverage validates the live-pending case, the no-invitation and post-accept cases, and a multi-org scenario. Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -30,6 +30,10 @@ type Identity implements Node {
|
||||
before: CursorKey
|
||||
): PersonalAPIKeyConnection @goField(forceResolver: true)
|
||||
|
||||
invitingOrganizations: [Organization!]!
|
||||
@goField(forceResolver: true)
|
||||
@session(required: PRESENT)
|
||||
|
||||
ssoLoginURL: String
|
||||
@goField(forceResolver: true)
|
||||
@session(required: PRESENT)
|
||||
|
||||
@@ -130,6 +130,26 @@ func (r *identityResolver) PersonalAPIKeys(ctx context.Context, obj *types.Ident
|
||||
return types.NewPersonalAPIKeyConnection(page, r, obj.ID), nil
|
||||
}
|
||||
|
||||
// InvitingOrganizations is the resolver for the invitingOrganizations field.
|
||||
func (r *identityResolver) InvitingOrganizations(ctx context.Context, obj *types.Identity) ([]*types.Organization, error) {
|
||||
if _, err := r.authorize(ctx, obj.ID, iam.ActionInvitationList, authz.WithSkipAssumptionCheck()); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
organizations, err := r.iam.AccountService.ListInvitingOrganizations(ctx, obj.ID)
|
||||
if err != nil {
|
||||
r.logger.ErrorCtx(ctx, "cannot list inviting organizations", log.Error(err))
|
||||
return nil, gqlutils.Internal(ctx)
|
||||
}
|
||||
|
||||
result := make([]*types.Organization, len(organizations))
|
||||
for i, organization := range organizations {
|
||||
result[i] = types.NewOrganization(organization)
|
||||
}
|
||||
|
||||
return result, nil
|
||||
}
|
||||
|
||||
// SsoLoginURL is the resolver for the ssoLoginURL field.
|
||||
func (r *identityResolver) SsoLoginURL(ctx context.Context, obj *types.Identity) (*string, error) {
|
||||
if _, err := r.authorize(ctx, obj.ID, iam.ActionIdentityGet); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user