|
| 1 | +import { Prisma, prisma } from "~/db.server"; |
| 2 | +import { logger } from "~/services/logger.server"; |
| 3 | +import { rbac } from "~/services/rbac.server"; |
| 4 | + |
| 5 | +export type EnsureOrgMemberParams = { |
| 6 | + userId: string; |
| 7 | + organizationId: string; |
| 8 | + // null = use the seeded MEMBER role from the existing enum. A non-null |
| 9 | + // value is an RBAC role id; when an RBAC plugin is installed it gets |
| 10 | + // attached after the OrgMember row is created. |
| 11 | + roleId: string | null; |
| 12 | + source: "sso_jit" | "invite" | "manual"; |
| 13 | +}; |
| 14 | + |
| 15 | +export type EnsureOrgMemberResult = { created: boolean; orgMemberId: string }; |
| 16 | + |
| 17 | +// Idempotent OrgMember upsert. If the (userId, organizationId) row |
| 18 | +// already exists this is a no-op (returns `{ created: false }`); we do |
| 19 | +// NOT touch the existing role to avoid demoting a user that JIT happens |
| 20 | +// to fire for again. |
| 21 | +// |
| 22 | +// Seat-limit enforcement lives at the call sites — every existing |
| 23 | +// OrgMember insert in the codebase does its own seat check before |
| 24 | +// calling in. This helper deliberately does none (SSO JIT and |
| 25 | +// invite-accept are exempt by policy). |
| 26 | +export async function ensureOrgMember( |
| 27 | + params: EnsureOrgMemberParams |
| 28 | +): Promise<EnsureOrgMemberResult> { |
| 29 | + const { userId, organizationId, roleId, source } = params; |
| 30 | + |
| 31 | + const existing = await prisma.orgMember.findFirst({ |
| 32 | + where: { userId, organizationId }, |
| 33 | + select: { id: true }, |
| 34 | + }); |
| 35 | + if (existing) { |
| 36 | + return { created: false, orgMemberId: existing.id }; |
| 37 | + } |
| 38 | + |
| 39 | + // Two concurrent JIT/invite flows can both miss the findFirst above and |
| 40 | + // race to create the same (userId, organizationId) row; the unique |
| 41 | + // constraint makes one lose with P2002. Treat that as the idempotent |
| 42 | + // "already a member" case rather than letting it break sign-in. |
| 43 | + let member: { id: string }; |
| 44 | + try { |
| 45 | + member = await prisma.orgMember.create({ |
| 46 | + data: { |
| 47 | + userId, |
| 48 | + organizationId, |
| 49 | + role: "MEMBER", |
| 50 | + }, |
| 51 | + select: { id: true }, |
| 52 | + }); |
| 53 | + } catch (error) { |
| 54 | + if (error instanceof Prisma.PrismaClientKnownRequestError && error.code === "P2002") { |
| 55 | + const existingAfterConflict = await prisma.orgMember.findFirst({ |
| 56 | + where: { userId, organizationId }, |
| 57 | + select: { id: true }, |
| 58 | + }); |
| 59 | + if (existingAfterConflict) { |
| 60 | + return { created: false, orgMemberId: existingAfterConflict.id }; |
| 61 | + } |
| 62 | + } |
| 63 | + throw error; |
| 64 | + } |
| 65 | + |
| 66 | + if (roleId !== null) { |
| 67 | + const result = await rbac.setUserRole({ userId, organizationId, roleId }); |
| 68 | + if (!result.ok) { |
| 69 | + logger.warn("ensureOrgMember.setUserRole failed", { |
| 70 | + source, |
| 71 | + userId, |
| 72 | + organizationId, |
| 73 | + roleId, |
| 74 | + error: result.error, |
| 75 | + }); |
| 76 | + } |
| 77 | + } |
| 78 | + |
| 79 | + return { created: true, orgMemberId: member.id }; |
| 80 | +} |
0 commit comments