Wire applied-model enforcement across every controller

FeatureSecurityService
出荷済み
2026年4月19日 20:08 UTC
プロフィール
Kamo
コンテンツ
1640318

Every non-role setting on the applied security model is now enforced at the exact controller boundary it governs, and the scalar settings round-trip cleanly through the master/child model editors so the UI can gate on them. - **************** when branchTypeID is set, look up the branch type to derive the parent org; call assertSubChildOrgAllowed and assertAgeRangeAllowed for both member and team-member age slots before committing. New PATCH /{id}/visibility endpoint lets owners flip Organization.isPrivate, gated by assertCanSetPrivate. getAllOrganizations applies filterVisibleOrgsForViewer so results respect both allowOwnersViewOtherOrgs on the viewer's model and the isPrivate flag on candidates. - **************** call assertAppEnableAllowed / assertAppDisableAllowed so NOT_AVAILABLE apps can't be enabled and FORCE_ENABLED apps can't be disabled. - OAuthConfigController POST/PUT: assertCanManageIdentityProvider blocks provider CRUD when identityProviderSetting == NOT_AVAILABLE. - CommerceMarketController POST/PUT: assertCommerceTypeAllowed rejects a commerce type not listed in the model's appConfig for CRM. - SecurityModelController + MasterModelController: round-trip appConfigs through create/update payloads and the GET responses. New processAppConfigs helper accepts the list form used by the frontend editor. - AppliedModelController: response now includes the full scalar settings block (allowOwnersViewOtherOrgs, allowOwnersPrivateOrgs, allowSubChildOrgs, age ranges, identityProviderSetting, teamMemberPayFeesSetting) and the appConfigs map so frontend editors can gate uniformly. Also surfaces orgIsPrivate so the privacy toggle stays in sync.

すべての変更

配送を見るのが好きですか?

これらのアップデートは、自動的にワークスペースに埋め込まれます。 週1回無料スタートし、週1回生育する.

永遠に無料で始める料金を見る