Skip to content

fix(host-cloudflare): list the Access caller as the workspace member - #2169

Open
daviesayo wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
daviesayo:fix/cloudflare-access-member-row
Open

daviesayo wants to merge 1 commit into
UsefulSoftwareCo:mainfrom
daviesayo:fix/cloudflare-access-member-row

Conversation

@daviesayo

Copy link
Copy Markdown
Contributor

Summary

Since #2051 the console decides admin gating from /account/members, and the Cloudflare host's listMembers returned an empty list. Every Access user, including ADMIN_EMAILS admins, saw "Add integration" and "Browse integrations" disabled, while the server still granted them admin.

listMembers now returns the caller as the one active member. Its role follows the server's own admin rule (orgRole === "admin"), so the console and the API agree.

Verification

  • bun run format:check: all files pass.
  • bun run lint: 0 warnings, 0 errors.
  • bun run typecheck: run in apps/host-cloudflare (tsgo --noEmit), clean.
  • bun run test: run in apps/host-cloudflare, 41 of 41 pass.
  • e2e: new case in worker.e2e.node.test.ts (workerd via unstable_dev, dev auth), "lists the caller as the one active member, with the admin role the server grants". Without the fix it fails with expected [] to deeply equal [ { userId: 'dev', … } ]. With the fix it passes.
  • Live check: deployed to a self-hosted Cloudflare instance behind Access. Before the change, /api/account/members returned {"members":[]} and both buttons were disabled. After it, the endpoint returns one active admin row for the ADMIN_EMAILS user and both buttons are enabled.

Checklist

  • Added a changeset (@executor-js/host-cloudflare patch).
  • Added or updated tests for the new behaviour.
  • No secrets, credentials, or private data in the diff.

The console derives admin gating from /account/members since UsefulSoftwareCo#2051, and
the Cloudflare host returned an empty list. Every Access user, including
ADMIN_EMAILS admins, saw "Add integration" and "Browse integrations"
disabled even though the server still granted admin.

listMembers now returns the caller as one active member whose role
mirrors the server's own admin rule (orgRole === "admin").

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant