TerdutTeam: mint and surface a real invite link (spec.invite)
The actual fix for the human-onboarding gap niklas/terdut-server#23 found -- not a terdut-server change at all. A team-scoped credential is already owner-equivalent for POST/GET/DELETE /api/teams/{teamID}/invites (requireTeamOwner's synthetic-membership mechanism, ratified not accidental per that repo's SERVICE-ACCOUNTS.md), and invite redemption bypasses signup_mode entirely -- this TerdutTeam controller just never grew a feature to use either fact. New spec.invite{enabled, role (member|owner, default member), maxUses (1-100, default 1)} and status.inviteSecretRef. The Secret lives in the TerdutTeam's OWN namespace, not the operator's: unlike status.credentialsSecretRef (a durable, high-privilege credential, kept operator-side per DESIGN.md §6), an invite is bounded and limited-use, meant for this namespace's own human operators to read and hand out -- same precedent as TerdutAlertSource's status.webhookURLSecretRef, same- namespace and OwnerReference'd so deleting the TerdutTeam garbage-collects it automatically. internal/controller/terdutteam_invite.go: mints on first spec.invite.enabled, refreshes a day ahead of terdut-server's fixed 7-day TTL (reading the Secret's own stored expiresAt, no extra server round-trip per reconcile), revokes server-side and deletes the Secret when flipped back to false. A lost invite Secret is silently re-minted rather than treated as unrecoverable the way TerdutAlertSource's webhook key is -- nothing external holds a durable dependency on one specific invite link staying stable, it's read once by one human and handed out. New tdclient.Invite/CreateInvite/RevokeInvite. New envtest coverage: mint into the team's own namespace, refresh-before-expiry, revoke-on-disable (internal/controller/terdutteam_controller_test.go's new "spec.invite" Describe block), plus the fake server growing invite support (terdutserver_controller_test.go) -- its handleTeamSubPath dispatcher was split further (deadman switches into their own handleDeadmanSubPath, matching the existing handleIntegrationSubPath precedent) to stay under golangci-lint's gocyclo threshold with the new route added. examples/demo updated to prove this end to end: 02-team-platform.yaml turns on spec.invite; run-demo.sh's bootstrap_login/join_demo_teams (the psql signup_mode flip + a direct team_members INSERT) are replaced by redeem_platform_invite (reads status.inviteSecretRef, a real POST /api/signup with the invite token) and join_payments_team (POST /api/teams/{teamID}/members using Payments' own credential and alice's user id resolved via GET /api/users, deliberately not given its own spec.invite, so the demo shows both onboarding paths this feature unlocks) -- zero kubectl exec/psql calls remain anywhere in the script. README.md's "First login" section rewritten to match; it no longer documents the admin-token curl call that 403s against current terdut-server (niklas/terdut-server#23). Depends on niklas/terdut-server#24 (the callerMayManageServiceAccount fix for terdut-operator#3) being released before this is deployed for real -- not required to build or test this change itself, since the envtest fake never modeled that authorization gap to begin with.
This commit is contained in:
@@ -566,3 +566,50 @@ func (c *Client) DeleteIntegration(ctx context.Context, teamID, integrationID in
|
||||
}
|
||||
return c.do(req, nil)
|
||||
}
|
||||
|
||||
// Invite is a standing link into a team (POST /api/teams/{teamID}/invites'
|
||||
// own response shape). URL carries the raw token exactly once, at creation
|
||||
// -- terdut-server never shows it again (same one-time-shown shape as an
|
||||
// integration's webhook key) -- so a caller that needs it later has to have
|
||||
// kept this response, not re-fetched it.
|
||||
type Invite struct {
|
||||
ID int64 `json:"id"`
|
||||
TeamID int64 `json:"team_id"`
|
||||
Role string `json:"role"`
|
||||
ExpiresAt time.Time `json:"expires_at"`
|
||||
MaxUses int64 `json:"max_uses"`
|
||||
URL string `json:"url,omitempty"`
|
||||
}
|
||||
|
||||
// CreateInvite calls POST /api/teams/{teamID}/invites -- owner-gated
|
||||
// (requireTeamOwner), so c must hold this team's own team-scoped
|
||||
// credential, which already satisfies that check via its synthetic owner
|
||||
// membership (terdut-server's SERVICE-ACCOUNTS.md). No conflict handling
|
||||
// needed: unlike a team or a service account, an invite has no unique name
|
||||
// to collide on -- every call mints a brand new row.
|
||||
func (c *Client) CreateInvite(ctx context.Context, teamID int64, role string, maxUses int64) (*Invite, error) {
|
||||
req, err := c.newRequest(ctx, http.MethodPost, fmt.Sprintf("/api/teams/%d/invites", teamID),
|
||||
map[string]any{"role": role, "max_uses": maxUses})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var inv Invite
|
||||
if err := c.do(req, &inv); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &inv, nil
|
||||
}
|
||||
|
||||
// RevokeInvite calls DELETE /api/teams/{teamID}/invites/{inviteID} -- same
|
||||
// credential requirement as CreateInvite. A 404 (already revoked, or never
|
||||
// existed) is the caller's to treat as success if it wants to, the same way
|
||||
// DeleteTeam's own 404 handling works -- this method itself just reports
|
||||
// whatever terdut-server said.
|
||||
func (c *Client) RevokeInvite(ctx context.Context, teamID, inviteID int64) error {
|
||||
req, err := c.newRequest(ctx, http.MethodDelete,
|
||||
fmt.Sprintf("/api/teams/%d/invites/%d", teamID, inviteID), nil)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return c.do(req, nil)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user