Skip to content

Add game-scoped user-profile and permission queries for Head Admin team management - #867

Merged
frasermolyneux merged 3 commits into
mainfrom
copilot/add-game-scoped-queries
Sep 1, 2026
Merged

frasermolyneux merged 3 commits into
mainfrom
copilot/add-game-scoped-queries

Conversation

Copilot AI commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

GET /v1/user-profiles could filter moderators/admins by role claim but not by a specific GameType, forcing portal-web to fetch and filter in memory to build a per-game Head Admin management view. GetPermissionsReport also only matched game-scoped claim values, silently dropping server-scoped additional permissions that belong to a game via their game-server GUID.

Game-scoped user-profile filtering

  • Added a backward-compatible GetUserProfiles overload (IUserProfileApi, controller, typed V1 client, FakeUserProfileApi) accepting an optional GameType? gameType; existing 6-arg callers are unaffected.
  • Role type and game value must match on the same claim: HeadAdmins/GameAdmins/Moderators now filter ClaimType == role && ClaimValue == gameType, so an unrelated additional permission on another game no longer leaks a profile into the wrong game's list.
  • AnyAdmin keeps Webmaster/SeniorAdmin global while requiring game-scoped roles to match the requested game.
  • GameType.Unknown is treated as no game filter (consistent with existing GetPermissionsReport behavior).
  • Filtering is applied before filteredCount, ordering, Skip/Take, so pagination metadata reflects the game-scoped result set.
  • FakeUserProfileApi now implements real filter/search/order/pagination semantics instead of a stub.

Game-filtered permissions report

  • GetPermissionsReport(gameType, claimType) now includes both game-scoped claims (ClaimValue == gameType) and server-scoped claims whose ClaimValue resolves to a GameServer belonging to that game, via a small bounded server-ID lookup (no full table/claim scan).
  • Claims for other games' servers and orphaned/deleted server IDs are excluded.
// Only COD5 moderators, correctly paginated
await userProfileApi.GetUserProfiles(null, UserProfileFilter.Moderators, GameType.CallOfDuty5, 0, 50, null);

// Includes game-scoped + COD5-server-scoped permission grants, excludes other games
await userProfileApi.GetPermissionsReport(GameType.CallOfDuty5, null);

Tests

  • Extended UserProfileControllerTests with same-claim matching, exclusion, multi-game, search+pagination composition, and AnyAdmin/Unknown semantics cases.
  • Added typed-client query-serialization tests verifying gameType is only emitted when supplied.
  • Added FakeUserProfileApi behavioral tests.
  • Added V1 HTTP integration tests asserting response payloads and pagination metadata for both endpoints.

Co-authored-by: frasermolyneux <34033625+frasermolyneux@users.noreply.github.com>
Copilot AI changed the title [WIP] Add game-scoped user and permission queries for Head Admin team management Add game-scoped user-profile and permission queries for Head Admin team management Sep 1, 2026
Copilot AI requested a review from frasermolyneux September 1, 2026 15:22
@frasermolyneux
frasermolyneux marked this pull request as ready for review September 1, 2026 16:11
Copilot AI lite review requested due to automatic review settings September 1, 2026 16:11

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There are compatibility/performance concerns (public interface source-breaking for implementers and a potentially unbounded IN expansion in the permissions report query) that should be addressed before merging.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR extends the V1 user-profile and permissions-report endpoints to support game-scoped filtering, enabling portal-web to build per-game Head Admin management views without client-side filtering and to correctly include server-scoped permission claims tied to a game via server GUIDs.

Changes:

  • Added an optional gameType query parameter to GET /v1.0/user-profiles (API, abstractions, typed client, and testing fake), with same-claim game scoping for game-based role filters.
  • Enhanced GetPermissionsReport(gameType, claimType) to include both game-scoped claims and server-scoped claims whose server IDs belong to the requested game.
  • Added/extended unit, typed-client, fake-behavior, and V1 HTTP integration tests to cover composition, pagination metadata, and inclusion/exclusion rules.
File summaries
File Description
src/XtremeIdiots.Portal.Repository.Api.V1/Controllers/V1/UserProfileController.cs Adds gameType-aware filtering for user profiles and expands permissions report to include server-scoped claims for servers in the requested game.
src/XtremeIdiots.Portal.Repository.Api.Tests.V1/Controllers/V1/UserProfileControllerTests.cs Adds unit tests covering same-claim semantics, pagination/count correctness, and permissions-report inclusion/exclusion.
src/XtremeIdiots.Portal.Repository.Api.IntegrationTests.V1/UserProfilesTests.cs Adds HTTP integration tests for /user-profiles and /permissions-report with gameType, asserting payloads and pagination.
src/XtremeIdiots.Portal.Repository.Api.Client.V1/Api/V1/UserProfileApi.cs Adds an overload that emits gameType as a query parameter when provided.
src/XtremeIdiots.Portal.Repository.Api.Client.Tests.V1/UserProfileApiQuerySerializationTests.cs Verifies typed-client query serialization behavior for gameType (present/absent) and legacy overload behavior.
src/XtremeIdiots.Portal.Repository.Api.Client.Testing/Fakes/FakeUserProfileApi.cs Implements real filter/search/order/pagination semantics including the new game-scoped role filtering.
src/XtremeIdiots.Portal.Repository.Api.Client.Testing.Tests/FakeUserProfileApiTests.cs Adds behavioral tests for fake filtering and pagination semantics.
src/XtremeIdiots.Portal.Repository.Abstractions.V1/Interfaces/V1/IUserProfileApi.cs Extends the public V1 interface surface with a new GetUserProfiles(..., GameType? gameType, ...) overload.
Review details
  • Files reviewed: 8/8 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/XtremeIdiots.Portal.Repository.Api.Client.Testing/Fakes/FakeUserProfileApi.cs Outdated
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

github-actions Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor
⛔ Superseded — A newer run has replaced this result.

🏗️ Terraform Plan

🌍 Environment: dev

✅ Validate — Passed

✅ Plan

✅ No changes. Your infrastructure matches the configuration.

Co-authored-by: frasermolyneux <34033625+frasermolyneux@users.noreply.github.com>
auto-merge was automatically disabled September 1, 2026 17:05

Head branch was pushed to by a user without write access

@sonarqubecloud

sonarqubecloud Bot commented Sep 1, 2026

Copy link
Copy Markdown

Copilot AI deployed to Development September 1, 2026 17:21 Active
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

🏗️ Terraform Plan

🌍 Environment: dev

✅ Validate — Passed

✅ Plan

✅ No changes. Your infrastructure matches the configuration.

This branch was successfully deployed

1 active deployment
Development — f3ae691b Deployed Sep 1, 2026 by Copilot via terraform-plan-dev #603
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add game-scoped user and permission queries for Head Admin team management

3 participants