Enforce every non-role setting on ChildOrgSecurityModel

Featurekamo-shared-library
Ya
19 Aprili 2026, 20:07 UTC
Mwandishi
Kamo
Ahadi ya
59a5056

Adds end-to-end enforcement for the remaining settings on an org's applied security model. Every setting that was previously only read (or dropped on save) now has a persistence path, a runtime enforcement helper, and a UI hook to consume it. Data layer: - Organization.isPrivate (boolean column, default false) — org's own visibility flag, set through the new MasterModelController-gated PATCH endpoint. - ServiceAvailabilityType enum (OPTIONAL_DEFAULT_ENABLED / OPTIONAL_DEFAULT_DISABLED / NOT_AVAILABLE / FORCE_ENABLED). - ChildOrgSecurityModelAppConfig entity + repo + service — persists per-app availability (and CRM's allowedCommerceTypes) previously dropped on save. - **************** round-trips the new entity. Runtime enforcement: - AppliedModelEnforcementService consolidates every check used by callers: assertSubChildOrgAllowed, assertAgeRangeAllowed, **************** isIdentityProviderRequired, assertCanSetPrivate, filterVisibleOrgsForViewer, assertTeamMemberCanSelfPayFees, isTeamMemberPayFeesForced / Blocked, assertAppEnableAllowed, assertAppDisableAllowed, getAppAvailability, getDefaultEnabledAppsForChild, assertCommerceTypeAllowed, getAllowedCommerceTypes. Null-safe: "no applied model" permits everything. - ChildOrgTemplateSeedingService extended to also seed OrgFeature rows from the parent's appConfig defaults (FORCE_ENABLED and OPTIONAL_DEFAULT_ENABLED) on new child orgs, so newly-provisioned orgs come up with the right default surface.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei