Skip to content

bug: stop roster admins taking over team ownership - #433

Merged
lukepolo merged 3 commits into
mainfrom
bug/team-ownership-guard
Sep 29, 2026
Merged

lukepolo merged 3 commits into
mainfrom
bug/team-ownership-guard

Conversation

@lukepolo

@lukepolo lukepolo commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Stops a roster Admin from taking over a team, or from locking the owner out of their own roster.

  • tbu_teams: only the current owner or staff (admin, administrator, tournament_organizer) can change owner_steam_id, and the new owner must already be on the roster.
  • New tau_teams promotes the new owner to roster Admin. New tbu_team_roster keeps the owner's row at Admin, so ownership has to be transferred before the old owner can be demoted.
  • The roster cap trigger skips updates that keep the same status and team, so role edits still work on a roster that is already over a cap.
  • A backfill migration re-promotes owners who were already demoted.

Tests: roster-Admin takeover, handing the team to a non-member, owner demotion, new-owner promotion, the over-cap role change and the backfill (new test) each fail without the fix. Not covered: owners who left their own roster before tbd_team_roster existed.

Any roster Admin could write teams.owner_steam_id (to themselves or to
someone off the team) and could demote the owner's own roster row, locking
the owner out of roster edits. tbu_teams now lets only the owner or staff
move ownership and only to a roster member, tau_teams makes the new owner a
roster Admin, and tbu_team_roster keeps the owner's row an Admin. A
backfill restores owners already demoted.

tbiu_team_roster_status also stops re-checking caps on updates that leave
status and team alone, so role edits work on an over-cap roster.
@lukepolo
lukepolo merged commit cd5519b into main Sep 29, 2026
2 checks passed
@lukepolo
lukepolo deleted the bug/team-ownership-guard branch September 29, 2026 00:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant