Introduce updateWorkspaceMemberSettings and clarify product (#19441)
## Summary Introduces a dedicated **metadata** mutation to update **standard (non-custom)** workspace member settings, moves profile-related UI to use it, and aligns **workspace member** record permissions with the rest of the CRM so users cannot escalate visibility via RLS by editing their own member record. ## Product behaviour ### Profile and appearance (standard fields) - Users can still update **their own** standard workspace member fields that the product exposes in **Settings / Profile** (e.g. name, locale, color scheme, avatar flow) via the new **`updateWorkspaceMemberSettings`** mutation. - The mutation returns a **boolean**; the app **merges** the updated fields into local state so the UI stays in sync without refetching the full workspace member record. - **Locale** changes also keep **`userWorkspace`** in sync when a locale is present in the payload (including from the workspace `updateOne` path when applicable). ### Custom fields on workspace members - The dedicated metadata mutation **rejects** any **custom** workspace member field (and unknown keys). Those updates must go through the normal **object** `updateOne` pipeline, which is subject to **object- and field-level** permissions like other records. But since we don't have object- and field-level permission configuration for system objects yet, this permission is derived from Workspace member settings permission. - **Workspace member** is no longer exempt from ORM permission validation for updates merely because it is a **system** object. Users who **do not** have workspace member access (e.g. no **Workspace members** settings permission and no equivalent broad settings access on the role) **cannot** use `updateOne` on `workspaceMember` to change **custom** (or other) fields on their own row—even though that row is used for RLS predicates. - This closes a path where someone could widen what they can see by writing to fields that drive row-level rules. ### Who can change another member - Updating **another** user’s workspace member still requires **Workspace members** (or equivalent) settings permission, consistent with admin tooling.
This commit is contained in:
+2
@@ -118,6 +118,8 @@ export const WidgetActionFieldEdit = () => {
|
||||
isUIReadOnly: fieldMetadataItem.isUIReadOnly ?? false,
|
||||
isCustom: fieldMetadataItem.isCustom ?? false,
|
||||
},
|
||||
fieldDefinition,
|
||||
objectPermissionsByObjectMetadataId,
|
||||
}),
|
||||
anchorId: recordFieldInputInstanceId,
|
||||
} satisfies GenericFieldContextType;
|
||||
|
||||
+2
@@ -100,6 +100,8 @@ export const FieldWidgetDisplay = ({
|
||||
isUIReadOnly: fieldMetadataItem.isUIReadOnly ?? false,
|
||||
isCustom: fieldMetadataItem.isCustom ?? false,
|
||||
},
|
||||
fieldDefinition,
|
||||
objectPermissionsByObjectMetadataId,
|
||||
}),
|
||||
onMouseEnter: handleMouseEnter,
|
||||
anchorId: getRecordFieldInputInstanceId({
|
||||
|
||||
+11
-7
@@ -55,6 +55,14 @@ export const FieldsWidgetFieldItem = ({
|
||||
targetObjectNameSingular,
|
||||
);
|
||||
|
||||
const fieldDefinition = formatFieldMetadataItemAsColumnDefinition({
|
||||
field: fieldMetadataItem,
|
||||
position: globalIndex,
|
||||
objectMetadataItem,
|
||||
showLabel: true,
|
||||
labelWidth: 90,
|
||||
});
|
||||
|
||||
return (
|
||||
<FieldContext.Provider
|
||||
key={recordId + fieldMetadataItem.id}
|
||||
@@ -62,13 +70,7 @@ export const FieldsWidgetFieldItem = ({
|
||||
recordId,
|
||||
maxWidth: 200,
|
||||
isLabelIdentifier: false,
|
||||
fieldDefinition: formatFieldMetadataItemAsColumnDefinition({
|
||||
field: fieldMetadataItem,
|
||||
position: globalIndex,
|
||||
objectMetadataItem,
|
||||
showLabel: true,
|
||||
labelWidth: 90,
|
||||
}),
|
||||
fieldDefinition,
|
||||
useUpdateRecord,
|
||||
isDisplayModeFixHeight: true,
|
||||
isRecordFieldReadOnly: isRecordFieldReadOnly({
|
||||
@@ -83,6 +85,8 @@ export const FieldsWidgetFieldItem = ({
|
||||
isUIReadOnly: fieldMetadataItem.isUIReadOnly ?? false,
|
||||
isCustom: fieldMetadataItem.isCustom ?? false,
|
||||
},
|
||||
fieldDefinition,
|
||||
objectPermissionsByObjectMetadataId,
|
||||
}),
|
||||
onMouseEnter,
|
||||
anchorId: `${getRecordFieldInputInstanceId({
|
||||
|
||||
@@ -87,6 +87,8 @@ export const useWidgetActions = ({
|
||||
isUIReadOnly: fieldMetadataItem.isUIReadOnly ?? false,
|
||||
isCustom: fieldMetadataItem.isCustom ?? false,
|
||||
},
|
||||
fieldDefinition,
|
||||
objectPermissionsByObjectMetadataId,
|
||||
});
|
||||
|
||||
if (!isFieldReadOnly) {
|
||||
|
||||
Reference in New Issue
Block a user