Conversation
The console derives admin gating from /account/members since UsefulSoftwareCo#2051, and the Cloudflare host returned an empty list. Every Access user, including ADMIN_EMAILS admins, saw "Add integration" and "Browse integrations" disabled even though the server still granted admin. listMembers now returns the caller as one active member whose role mirrors the server's own admin rule (orgRole === "admin").
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since #2051 the console decides admin gating from
/account/members, and the Cloudflare host'slistMembersreturned an empty list. Every Access user, includingADMIN_EMAILSadmins, saw "Add integration" and "Browse integrations" disabled, while the server still granted them admin.listMembersnow returns the caller as the one active member. Its role follows the server's own admin rule (orgRole === "admin"), so the console and the API agree.Verification
bun run format:check: all files pass.bun run lint: 0 warnings, 0 errors.bun run typecheck: run inapps/host-cloudflare(tsgo --noEmit), clean.bun run test: run inapps/host-cloudflare, 41 of 41 pass.worker.e2e.node.test.ts(workerd viaunstable_dev, dev auth), "lists the caller as the one active member, with the admin role the server grants". Without the fix it fails withexpected [] to deeply equal [ { userId: 'dev', … } ]. With the fix it passes./api/account/membersreturned{"members":[]}and both buttons were disabled. After it, the endpoint returns one active admin row for theADMIN_EMAILSuser and both buttons are enabled.Checklist
@executor-js/host-cloudflarepatch).