mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
## Summary * Fixes extreme slowness (browser-crashing on filter) on `/org/[slug]/team` for orgs with 200+ members. * Root cause: `MemberRow`/`MemberActions` each independently subscribed to org-wide React Query data (roles, projects, permissions, feature flags) and rendered a hidden `UpdateRolesPanel` per row. Filtering caused hundreds of duplicate query observers to mount/unmount on every keystroke, each scheduling its own stale-timeout bookkeeping and blocking the main thread for multiple seconds. * Hoisted all org-wide data fetching (`useOrganizationRolesV2Query`, `useOrgProjectsInfiniteQuery`, `usePermissionsQuery`, `useSelectedOrganizationQuery`, `useIsFeatureEnabled`) to `MembersView` and passed the results down as props. * Replaced the per-row `useAsyncCheckPermissions` hook calls in `MemberActions` with the underlying pure `doPermissionsCheck` function memoized locally, removing their internal query subscriptions. * Simplified `useGetRolesManagementPermissions` to stop calling a query-fetching fallback hook that was unreachable given all current call sites already pass `permissions`/`orgSlug` directly. * Replaced 200 hidden per-row `UpdateRolesPanel` instances with a single shared instance owned by `MembersView`, opened via an `onManageAccess` callback. * Cached the regex built by `doPermissionsCheck`'s `toRegexpString` instead of rebuilding it on every permission check. Diagnosed from two Chrome performance traces of the team page while typing in the filter box (multi-second main-thread blocking tasks traced to React Query `QueryObserver` mount/unmount storms). ## Test plan - [X] `tsc --noEmit` clean (only one pre-existing, unrelated error in `packages/ui-patterns`) - [X] `eslint` clean on all changed files (only pre-existing warnings) - [X] `vitest run tests/components/Organization/TeamSettings` — 51 tests pass - [X] Manually verify filtering is smooth on an org with 200+ members <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Team Settings provides centralized member access and role management. * Members can update roles through the access-management panel. * **Improvements** * Permission checks now more accurately handle organization and project scopes, including wildcard patterns. * Member search is debounced for smoother filtering while typing. * Access-management actions use current organization members, roles, permissions, and feature settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
51 lines
1.5 KiB
TypeScript
51 lines
1.5 KiB
TypeScript
import { PermissionAction } from '@supabase/shared-types/out/constants'
|
|
|
|
import type { OrganizationMember } from '@/data/organizations/organization-members-query'
|
|
import { doPermissionsCheck } from '@/hooks/misc/useCheckPermissions'
|
|
import type { Permission, Role } from '@/types'
|
|
|
|
export const useGetRolesManagementPermissions = (
|
|
orgSlug?: string,
|
|
roles?: Role[],
|
|
permissions?: Permission[]
|
|
): { rolesAddable: Number[]; rolesRemovable: Number[] } => {
|
|
const rolesAddable: Number[] = []
|
|
const rolesRemovable: Number[] = []
|
|
if (!roles || !orgSlug) return { rolesAddable, rolesRemovable }
|
|
|
|
roles.forEach((role: Role) => {
|
|
const canAdd = doPermissionsCheck(
|
|
permissions,
|
|
PermissionAction.CREATE,
|
|
'auth.subject_roles',
|
|
{
|
|
resource: { role_id: role.id },
|
|
},
|
|
orgSlug
|
|
)
|
|
if (canAdd) rolesAddable.push(role.id)
|
|
|
|
const canRemove = doPermissionsCheck(
|
|
permissions,
|
|
PermissionAction.DELETE,
|
|
'auth.subject_roles',
|
|
{
|
|
resource: { role_id: role.id },
|
|
},
|
|
orgSlug
|
|
)
|
|
if (canRemove) rolesRemovable.push(role.id)
|
|
})
|
|
|
|
return { rolesAddable, rolesRemovable }
|
|
}
|
|
|
|
export const hasMultipleOwners = (members: OrganizationMember[] = [], roles: Role[] = []) => {
|
|
const membersWhoAreOwners = members.filter((member) => {
|
|
const [memberRoleId] = member.role_ids ?? []
|
|
const role = roles.find((role: Role) => role.id === memberRoleId)
|
|
return role?.name === 'Owner' && !member.invited_at
|
|
})
|
|
return membersWhoAreOwners.length > 1
|
|
}
|