Add admins to cohort member list on access (ARB-510)#389
Merged
Conversation
When an admin connects to a cohort via WebSocket, they should be automatically added to the global cohort_member table if they're not already a member. This ensures the admin cohort member list accurately reflects who has accessed the cohort. Previously, admins were allowed to access any cohort due to the is_admin authorization check, but they were never added to the cohort member list. Now, after authentication, we ensure admins are added as members of the cohort they're accessing.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When an admin accesses a cohort via WebSocket, they are now automatically added to the global cohort member list. Previously, admins could access any cohort due to authorization bypass, but they weren't recorded as members of the cohort.
Changes
authenticatefunction inbackend/src/handle_socket.rsto add admins to the cohort_member table on first accessadd_member_by_user_idto insert the admin into the cohort_member table with no initial balance setTesting