Ashim and GitHub
5a45bcbc8f
feat: production-grade RBAC with editor role, custom roles, API key scoping, and audit log ( #89 )
...
* feat(rbac): add editor role, 3 new permissions, ownership helper
* feat(rbac): add audit_log table, apiKeys.permissions column, editor role to schema
* feat(rbac): wire requirePermission into all routes, add editor role support
* refactor(rbac): replace ad-hoc role checks with permission-based ownership
* feat(rbac): add audit log DB writes + query endpoint
Dual-write audit events to stdout (existing) and SQLite audit_log table.
Add GET /api/v1/audit-log with pagination, action filter, and date range
filtering, gated behind audit:read permission.
* feat(rbac): add API key permission scoping with ceiling enforcement
* feat(rbac): add escalation prevention and last-admin protection
* feat(rbac): add editor role to UI, API key permission scoping in settings
* test(rbac): add full permission matrix integration test
* test(rbac): add editor role E2E tests
* feat(rbac): add custom roles with CRUD API and DB-backed permission lookup
* feat(rbac): add API key expiration
* feat(rbac): add roles management UI and API key expiration to settings
* feat(rbac): add audit log UI to settings
* fix: remove any cast in API key permission validation
* test(rbac): add unit tests for username validation rules
* test(rbac): add unit tests for effective permissions and ownership
* test(rbac): add comprehensive route permission matrix (all routes × all roles)
* test(rbac): add auth route edge case tests (login failures, session expiry, password side effects)
* test(rbac): add escalation prevention tests (register, update, self-demote, last-admin)
* test(rbac): add ownership enforcement tests (files, pipelines, editor access, cross-user isolation)
* test(rbac): add API key edge cases (name validation, delete behavior, key revocation)
* test(rbac): add audit log edge cases (all events, pagination clamping, structure)
* test(rbac): add custom roles edge case tests (validation, CRUD, functional permissions)
* test(rbac): add comprehensive E2E tests (roles UI, audit log, custom role, API key scoping)
2026-04-22 18:10:04 +08:00
Siddharth Kumar Sah
85b1cfc10a
chore: rename Stirling-Image to ashim across entire codebase
...
Complete rebrand from Stirling-Image to ashim following the project
move to https://github.com/ashim-hq/ashim .
Changes across 117 files:
- Package scope: @stirling-image/* → @ashim/*
- GitHub URLs: stirling-image/stirling-image → ashim-hq/ashim
- Docker Hub: stirlingimage/stirling-image → ashimhq/ashim
- GitHub Pages: stirling-image.github.io → ashim-hq.github.io
- All branding text: "Stirling Image" → "ashim"
- Docker service/volumes/user: stirling → ashim
- Database: stirling.db → ashim.db
- localStorage keys: stirling-token → ashim-token
- Environment variables: STIRLING_GPU → ASHIM_GPU
- Python cache dirs: .cache/stirling-image → .cache/ashim
- SVG filter IDs, test prefixes, and all other references
2026-04-14 20:55:42 +08:00
Siddharth Kumar Sah
cc8a27239b
fix: complete RBAC implementation lost during merge
...
Several RBAC features from feat/rbac-permissions were silently lost
during the merge into main. This restores and completes them:
- Add permissions and teamName to login/session API responses
- Export Permission and Role types from shared package
- Filter settings tabs by user permissions in frontend
- Extend useAuth hook with role, permissions, and hasPermission
- Restrict teams listing to admin only
- Add admin override for API keys, files, and pipelines listing
- Add ownership scoping to file access, download, and delete routes
- Register userFileRoutes in integration test server
- Mock auth import in unit permissions test to avoid SQLite lock
2026-04-10 21:25:30 +08:00