feat(admission): add scheduled group access
This commit is contained in:
@@ -125,8 +125,10 @@ export function isGameNetworkAllowed(
|
||||
export function gameAdmissionDenialReason(
|
||||
group: { accessEnabled: boolean; anonymizedNetworksAllowed: boolean } | null,
|
||||
classification: "unknown" | "clear" | "vpn" | "proxy" | "hosting" | "tor",
|
||||
scheduleAllowed = true,
|
||||
) {
|
||||
if (!group?.accessEnabled) return "group_access_disabled" as const;
|
||||
if (!scheduleAllowed) return "schedule_disallowed" as const;
|
||||
if (!isGameNetworkAllowed(classification, group.anonymizedNetworksAllowed)) {
|
||||
return "anonymized_network_disallowed" as const;
|
||||
}
|
||||
|
||||
@@ -31,12 +31,14 @@ describe("group-based admission", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("prioritizes disabled group access before the network exception policy", () => {
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: false, anonymizedNetworksAllowed: false }, "vpn"))
|
||||
it("prioritizes disabled group access, then schedule, then network policy", () => {
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: false, anonymizedNetworksAllowed: false }, "vpn", false))
|
||||
.toBe("group_access_disabled");
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: true, anonymizedNetworksAllowed: false }, "vpn"))
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: true, anonymizedNetworksAllowed: false }, "vpn", false))
|
||||
.toBe("schedule_disallowed");
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: true, anonymizedNetworksAllowed: false }, "vpn", true))
|
||||
.toBe("anonymized_network_disallowed");
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: true, anonymizedNetworksAllowed: true }, "vpn"))
|
||||
expect(gameAdmissionDenialReason({ accessEnabled: true, anonymizedNetworksAllowed: true }, "vpn", true))
|
||||
.toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
CREATE TABLE "group_access_windows" (
|
||||
"id" uuid PRIMARY KEY DEFAULT gen_random_uuid() NOT NULL,
|
||||
"group_id" uuid NOT NULL,
|
||||
"start_minute_of_week" integer NOT NULL,
|
||||
"end_minute_of_week" integer NOT NULL,
|
||||
"created_at" timestamp (3) with time zone DEFAULT now() NOT NULL,
|
||||
CONSTRAINT "group_access_windows_minute_range_check" CHECK ("group_access_windows"."start_minute_of_week" >= 0 and "group_access_windows"."start_minute_of_week" < 10080 and "group_access_windows"."end_minute_of_week" >= 0 and "group_access_windows"."end_minute_of_week" < 10080 and "group_access_windows"."start_minute_of_week" <> "group_access_windows"."end_minute_of_week")
|
||||
);
|
||||
--> statement-breakpoint
|
||||
ALTER TABLE "app_settings" ADD COLUMN "scheduled_access_denied_message" text DEFAULT 'Your group is only allowed access from {next_start} to {next_end}.' NOT NULL;--> statement-breakpoint
|
||||
ALTER TABLE "group_access_windows" ADD CONSTRAINT "group_access_windows_group_id_groups_id_fk" FOREIGN KEY ("group_id") REFERENCES "public"."groups"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||
CREATE INDEX "group_access_windows_group_idx" ON "group_access_windows" USING btree ("group_id");
|
||||
File diff suppressed because it is too large
Load Diff
@@ -36,6 +36,13 @@
|
||||
"when": 1785678753029,
|
||||
"tag": "0004_zippy_silver_centurion",
|
||||
"breakpoints": true
|
||||
},
|
||||
{
|
||||
"idx": 5,
|
||||
"version": "7",
|
||||
"when": 1785692345708,
|
||||
"tag": "0005_young_vertigo",
|
||||
"breakpoints": true
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,7 +1,9 @@
|
||||
import { sql } from "drizzle-orm";
|
||||
import {
|
||||
boolean,
|
||||
check,
|
||||
index,
|
||||
integer,
|
||||
inet,
|
||||
jsonb,
|
||||
pgEnum,
|
||||
@@ -80,6 +82,26 @@ export const groups = pgTable(
|
||||
],
|
||||
);
|
||||
|
||||
export const groupAccessWindows = pgTable(
|
||||
"group_access_windows",
|
||||
{
|
||||
id: uuid("id").primaryKey().defaultRandom(),
|
||||
groupId: uuid("group_id")
|
||||
.notNull()
|
||||
.references(() => groups.id, { onDelete: "cascade" }),
|
||||
startMinuteOfWeek: integer("start_minute_of_week").notNull(),
|
||||
endMinuteOfWeek: integer("end_minute_of_week").notNull(),
|
||||
createdAt: createdAt(),
|
||||
},
|
||||
(table) => [
|
||||
index("group_access_windows_group_idx").on(table.groupId),
|
||||
check(
|
||||
"group_access_windows_minute_range_check",
|
||||
sql`${table.startMinuteOfWeek} >= 0 and ${table.startMinuteOfWeek} < 10080 and ${table.endMinuteOfWeek} >= 0 and ${table.endMinuteOfWeek} < 10080 and ${table.startMinuteOfWeek} <> ${table.endMinuteOfWeek}`,
|
||||
),
|
||||
],
|
||||
);
|
||||
|
||||
export const userGroupMemberships = pgTable(
|
||||
"user_group_memberships",
|
||||
{
|
||||
@@ -178,6 +200,9 @@ export const appSettings = pgTable("app_settings", {
|
||||
vpnDeniedMessage: text("vpn_denied_message")
|
||||
.notNull()
|
||||
.default("VPN, proxy, and Tor connections are not allowed. Contact a host to request an exception."),
|
||||
scheduledAccessDeniedMessage: text("scheduled_access_denied_message")
|
||||
.notNull()
|
||||
.default("Your group is only allowed access from {next_start} to {next_end}."),
|
||||
...timestamps(),
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user