Skip to content

feat(groups): configure default permissions and AD group sync (PPT-2819) - #311

Merged
MrYuion merged 1 commit into
developfrom
feat/PPT-2819-group-permissions
Sep 29, 2026
Merged

MrYuion merged 1 commit into
developfrom
feat/PPT-2819-group-permissions

Conversation

@MrYuion

@MrYuion MrYuion commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Groups now have default_permissions and ad_group_mappings (PlaceOS/models ba1c194, c0c235e). Users added to a group without permissions get the default. Users in a mapped AD group are added to the group automatically. Backoffice cannot set either field.

Jira: PPT-2819. The recording is on the Jira issue. This PR covers backoffice only. Signage manager is a separate change.

Fix

  • The group form has a Default permissions section with one toggle for each permission.
  • The group form has an AD group sync section. Each mapped AD group shows its name, ID and permissions. You can edit or remove it.
    • If the current domain has an Office 365 staff API tenant, you find AD groups with /api/staff/v1/groups. Otherwise, you type the AD group ID and name.
    • A new mapping starts with the group's default permissions. You can change the permissions for each AD group.
    • Adding an AD group that is already mapped keeps its permissions.
  • To find the tenant, the form uses /api/staff/v1/tenants. Only admins can read that list, so for other users the form tries the group search instead.
  • The group About tab shows the default permissions and the mapped AD groups.
  • Bulk add users on a group starts with the group's default permissions. Single adds already leave out permissions, so the backend applies the default.
  • Bump @placeos/ts-client to 6.7.0. That release adds PlaceGroup.default_permissions, PlaceGroup.ad_group_mappings and PlaceGroupUser.auto_assigned (PlaceOS/ts-client 0ac9150).

Checks

  • bun run test:ci: 82 files, 953 tests pass. New tests cover mapping ID normalisation, add/remove/edit in the AD group field, tenant detection with the non-admin fallback, and the bulk add default.
  • bun run lint, tsc, bun run build: pass.
  • Tested in mock mode with temporary group and staff API mocks. The mocks are not committed.

Not verified on a live Office 365 tenant: the non-admin check sends /api/staff/v1/groups?q= with an empty query.


Made by Claude Opus 5.5 (1M context) in Claude Code (T3 Code).

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
backoffice Ready Ready Preview Sep 29, 2026 6:47am UTC

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@MrYuion
MrYuion merged commit 76bc58c into develop Sep 29, 2026
7 of 8 checks passed
@MrYuion
MrYuion deleted the feat/PPT-2819-group-permissions branch September 29, 2026 07:58

This branch was successfully deployed

1 active deployment
Preview — 910d15f5 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant