feat(api): capability enforcement on writes

Add lib/api/cap.js: requireWrite(entity_type) maps HTTP method to
action, runs canAct, and tags req.capTier as allow|suggest|deny→403.
Mutating routes (pages, projects, tasks, refs, resources, source_docs)
now check req.capTier and either run the repo (allow) or divert to
pending_changes returning 202 (suggest). Owner and worker actors stay
on the allow path. requireOwner helper added for Task 11.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
root
2026-05-31 21:03:52 +10:00
parent 7862d22a03
commit 56805053f0
8 changed files with 225 additions and 5 deletions

View File

@@ -3,6 +3,7 @@ import { z } from 'zod';
import * as repo from '../../db/repos/projects.js';
import { validate } from '../validate.js';
import { NotFoundError, ValidationError, asyncWrap } from '../errors.js';
import { requireWrite, divertToPending } from '../cap.js';
const STATUSES = ['idea', 'active', 'paused', 'done', 'abandoned'];
@@ -37,10 +38,15 @@ spacesScopedRouter.get('/',
);
spacesScopedRouter.post('/',
requireWrite('project'),
validate({ params: spaceParams, body: createSchema }),
asyncWrap(async (req, res) => {
const payload = { ...req.body, space_id: req.params.space_id };
if (req.capTier === 'suggest') {
return divertToPending(req, res, { entity_type: 'project', action: 'create', payload });
}
try {
const row = await repo.create({ ...req.body, space_id: req.params.space_id }, req.actor);
const row = await repo.create(payload, req.actor);
res.status(201).json(row);
} catch (e) {
if (e.code === '23503') throw new ValidationError('invalid space', { space_id: req.params.space_id });
@@ -59,20 +65,32 @@ router.get('/:id',
);
router.patch('/:id',
requireWrite('project'),
validate({ params: idParams, body: patchSchema }),
asyncWrap(async (req, res) => {
const existing = await repo.getById(req.params.id);
if (!existing) throw new NotFoundError('project not found');
if (req.capTier === 'suggest') {
return divertToPending(req, res, {
entity_type: 'project', entity_id: req.params.id, action: 'update', payload: req.body
});
}
const row = await repo.update(req.params.id, req.body, req.actor);
res.json(row);
})
);
router.delete('/:id',
requireWrite('project'),
validate({ params: idParams }),
asyncWrap(async (req, res) => {
const existing = await repo.getById(req.params.id);
if (!existing) throw new NotFoundError('project not found');
if (req.capTier === 'suggest') {
return divertToPending(req, res, {
entity_type: 'project', entity_id: req.params.id, action: 'delete', payload: {}
});
}
await repo.del(req.params.id, req.actor);
res.status(204).end();
})