Declare permissions on the plugin declaration

Clusterio #988 added a permissions array to PluginDeclaration and a
type level Permissions registry, and made checkPermission and the web
UI hasPermission helpers take PermissionName. Move the definePermission
calls of exp_groups and exp_scenario into the declaration and add the
names to the registry so the web pages type check. The browser
tsconfigs include index.ts so the augmentation is visible to the web
bundle, matching the in-repo plugins.

The exp_scenario table keeps its tuple form and derives the name union
from it, so a new row is still one line. Seed role permissions are typed
as PermissionName, so a typo in seed.ts is now a compile error rather
than a warning at seed time. The tests register the declared
permissions through registerPluginPermissions instead of importing
permissions.ts for its side effect.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
bbassie
2026-09-11 23:27:17 +00:00
co-authored by Claude Fable 5.1
parent 24d2f76a35
commit 30f1b5ea75
8 changed files with 192 additions and 153 deletions
+26 -22
View File
@@ -1,29 +1,14 @@
import * as lib from "@clusterio/lib";
import * as messages from "./messages";
// Defines a permission for every in game action and role flag used by the scenario
import "./permissions";
lib.definePermission({
name: "exp_scenario.config.view",
title: "View ExpScenario Config",
description: "View the config for all submodules of ExpScenario",
});
lib.definePermission({
name: "exp_scenario.config.edit",
title: "Edit ExpScenario Config",
description: "Edit the config for all submodules of ExpScenario",
});
lib.definePermission({
name: "exp_scenario.seed",
title: "Seed ExpScenario roles and groups",
description: "Create the roles and permission groups the scenario shipped with",
});
import { permissions as scenarioPermissions, type ScenarioPermissionName } from "./permissions";
declare module "@clusterio/lib" {
// Everything checked in game through exp_roles, plus the permissions checked on the controller
export interface Permissions extends Record<ScenarioPermissionName, never> {
"exp_scenario.config.view": never;
"exp_scenario.config.edit": never;
"exp_scenario.seed": never;
}
}
export const plugin: lib.PluginDeclaration = {
@@ -37,5 +22,24 @@ export const plugin: lib.PluginDeclaration = {
messages.SeedRequest,
],
permissions: [
...scenarioPermissions,
{
name: "exp_scenario.config.view",
title: "View ExpScenario Config",
description: "View the config for all submodules of ExpScenario",
},
{
name: "exp_scenario.config.edit",
title: "Edit ExpScenario Config",
description: "Edit the config for all submodules of ExpScenario",
},
{
name: "exp_scenario.seed",
title: "Seed ExpScenario roles and groups",
description: "Create the roles and permission groups the scenario shipped with",
},
],
webEntrypoint: "./web",
};
+11 -7
View File
@@ -1,4 +1,4 @@
import * as lib from "@clusterio/lib";
import type * as lib from "@clusterio/lib";
/**
* Permissions checked by the scenario in game through exp_roles.
@@ -7,9 +7,9 @@ import * as lib from "@clusterio/lib";
* underscores, see module/commands/_authorities.lua. Everything else is checked
* by name at its call site.
*/
type Definition = [name: string, title: string, description: string, grantByDefault?: boolean];
type Definition<Name extends string = string> = readonly [name: Name, title: string, description: string, grantByDefault?: boolean];
const definitions: Definition[] = [
const definitions = [
["exp_scenario.bypass.deconstruction_log", "Deconstruction log bypass", "Be excluded from the deconstruction log."],
["exp_scenario.bypass.entity_protection", "Bypass entity protection", "Remove entities that the protection filter would block."],
["exp_scenario.bypass.nuke_protection", "Bypass nuke protection", "Use nukes without the nuke protection restrictions."],
@@ -118,8 +118,12 @@ const definitions: Definition[] = [
["exp_scenario.player.admin", "Factorio admin", "Be promoted to Factorio admin while holding a role with this permission."],
["exp_scenario.player.instant_respawn", "Instant respawn", "Respawn after two seconds instead of the default delay."],
["exp_scenario.player.spectator", "Spectator", "Remove the zoom to world noise effect, as Factorio does for spectators."],
];
] as const satisfies readonly Definition[];
for (const [name, title, description, grantByDefault] of definitions) {
lib.definePermission({ name, title, description, grantByDefault });
}
/** Name of a permission defined by the scenario, added to lib.Permissions in index.ts. */
export type ScenarioPermissionName = (typeof definitions)[number][0];
export const permissions = definitions.map((definition: Definition<ScenarioPermissionName>): lib.PermissionDefinition => {
const [name, title, description, grantByDefault] = definition;
return { name, title, description, grantByDefault };
});
+3 -2
View File
@@ -1,3 +1,4 @@
import type * as lib from "@clusterio/lib";
import { RoleColor } from "@expcluster/roles";
/**
@@ -19,7 +20,7 @@ export interface SeedRole {
isAdmin?: boolean;
/** Name of the role whose permissions are also granted, applied recursively. */
parent?: string;
permissions: string[];
permissions: lib.PermissionName[];
/**
* Name of the seed group holders are placed in by their highest role.
* Without one the holders stay in Factorio's Default group.
@@ -329,7 +330,7 @@ export const seedGroups: SeedGroup[] = [
/** The permissions a seed role grants, including those of its parents. */
export function flattenSeedPermissions(role: SeedRole, roles = seedRoles) {
const permissions = new Set<string>();
const permissions = new Set<lib.PermissionName>();
const seen = new Set<string>();
let current: SeedRole | undefined = role;
while (current && !seen.has(current.name)) {
+4 -2
View File
@@ -11,8 +11,10 @@ const { ControllerPlugin: RolesPlugin } = require("@expcluster/roles/dist/node/c
const { ControllerPlugin: GroupsPlugin } = require("@expcluster/permission-groups/dist/node/controller");
const { GroupRecord, GroupPermissions, RoleMappingRecord } = require("@expcluster/permission-groups");
// Importing this defines the permissions the seed grants
require("../dist/node/permissions");
const { plugin } = require("../dist/node/index");
// Registering the plugin defines the permissions the seed grants
lib.registerPluginPermissions([plugin]);
// The controller validates message classes against the link registry
for (const Message of [messages.SeedRequest, ...roles.plugin.messages, ...groups.plugin.messages]) {
+4 -2
View File
@@ -3,8 +3,10 @@ const t = require("tap");
const lib = require("@clusterio/lib");
const { seedRoles, seedGroups, flattenSeedPermissions } = require("../dist/node/seed");
// Importing this defines the permissions the seed grants
require("../dist/node/permissions");
const { plugin } = require("../dist/node/index");
// Registering the plugin defines the permissions the seed grants
lib.registerPluginPermissions([plugin]);
t.test("seedRoles[] grant only defined permissions", t2 => {
for (const role of seedRoles) {
+1 -1
View File
@@ -1,4 +1,4 @@
{
"extends": "../tsconfig.browser.json",
"include": [ "web/**/*.tsx", "web/**/*.ts", "messages.ts", "package.json" ],
"include": [ "web/**/*.tsx", "web/**/*.ts", "index.ts", "messages.ts", "permissions.ts", "package.json" ],
}