Address review on the role api

- Roles are objects and everything done to or with a role is a method on it:
  assign, unassign, has_player, has_permission, is_higher_than,
  is_lower_than, get_players, get_player_names, print. Assignment has one
  entry point, role:assign(player, options), with local_only as an option
  rather than a second function.
- Roles are looked up by clusterio id with get_role; get_role_by_name searches
  the list for the few places, such as configs, which only know a name. The
  name map and the ordered list are gone, get_roles sorts on demand and the
  index field is replaced by the comparison methods.
- Players are LuaPlayer objects only, with nil or index 0 for the server.
- get_higher_roles and get_lower_roles replace print_to_roles_higher and
  print_to_roles_lower, call sites loop over them with role:print.
- Permission groups are removed from roles again, exp_groups owns the mapping
  from roles to groups.
- Seeding is a SeedRolesRequest behind a button on the roles page rather than
  running on first start, and creates only the roles; the player assignments
  are dropped. The seed lists each permission once at the lowest role which
  has it and lets the parent chain carry it up.
- System commands unlock for core.admin rather than a permission of their own.
- Role metatables are registered with Storage.register_metatable so the
  methods survive save and load, which the role records in storage needed.
- The player list auth uses Roles.player_outranks directly, and the event
  carries role ids rather than names.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
bbassie
2026-08-19 15:52:50 +00:00
co-authored by Claude Fable 5
parent 78a533a6f6
commit bea8d46c82
18 changed files with 330 additions and 506 deletions
+6 -24
View File
@@ -1,7 +1,7 @@
import { BaseControllerPlugin, InstanceRecord } from "@clusterio/controller";
import * as lib from "@clusterio/lib";
import * as messages from "./messages";
import { SeedRole, seedRoles, seedAssignments, flattenSeedPermissions } from "./seed";
import { SeedRole, seedRoles, flattenSeedPermissions } from "./seed";
import * as path from "node:path";
export class ControllerPlugin extends BaseControllerPlugin {
@@ -17,12 +17,6 @@ export class ControllerPlugin extends BaseControllerPlugin {
).bootstrap()
);
// An empty datastore means the plugin has not run before, so the roles
// the scenario used to define are created on the controller
if (this.roleMeta.size === 0) {
this.seed();
}
// The datastore can be out of step with the roles, either because the
// plugin was installed after they were created or because it was
// uninstalled while they were deleted
@@ -41,6 +35,7 @@ export class ControllerPlugin extends BaseControllerPlugin {
this.controller.handle(messages.RoleListRequest, this.handleRoleListRequest.bind(this));
this.controller.handle(messages.RoleMetaUpdateRequest, this.handleRoleMetaUpdateRequest.bind(this));
this.controller.handle(messages.SeedRolesRequest, this.handleSeedRolesRequest.bind(this));
this.controller.handle(messages.AssignmentListRequest, this.handleAssignmentListRequest.bind(this));
this.controller.handle(messages.AssignmentUpdateRequest, this.handleAssignmentUpdateRequest.bind(this));
@@ -55,18 +50,16 @@ export class ControllerPlugin extends BaseControllerPlugin {
*/
/**
* Create the roles the scenario shipped with and give the players it listed
* their roles. Roles which already exist by name are reused.
* Create the roles the scenario shipped with. Roles which already exist
* by name are reused and only gain the seed permissions.
*/
seed() {
const idsByName = new Map<string, number>();
async handleSeedRolesRequest() {
for (const [index, seedRole] of seedRoles.entries()) {
const role = this.seedRole(seedRole);
if (!role) {
continue;
}
idsByName.set(seedRole.name, role.id);
this.roleMeta.set(new messages.RoleMetaRecord(
role.id,
index + 1,
@@ -74,23 +67,12 @@ export class ControllerPlugin extends BaseControllerPlugin {
seedRole.shortHand,
"",
seedRole.color,
seedRole.permissionGroup,
seedRole.autoAssignHours === undefined ? null : seedRole.autoAssignHours * 3600000,
seedRole.blockAutoAssign ?? false,
));
}
for (const [name, roleNames] of Object.entries(seedAssignments)) {
const roleIds = roleNames.map(roleName => idsByName.get(roleName)).filter(id => id !== undefined);
if (roleIds.length !== roleNames.length) {
this.logger.warn(`Seed assignment for ${name} names a role which does not exist`);
}
const user = this.controller.users.getOrCreateUser(name);
user.set("roleIds", new Set([...user.roleIds, ...roleIds]));
this.controller.userPermissionsUpdated(user);
}
this.logger.info(`Seeded ${seedRoles.length} roles and ${Object.keys(seedAssignments).length} assignments`);
this.logger.info(`Seeded ${seedRoles.length} roles`);
}
/** Find or create the clusterio role for a seed role, returns undefined if it has no role to use. */