feat: bitwise RBAC engine with channel-level permission overrides

Replace string-based role checks (role === 'admin') with a bitwise BigInt
permission system. Adds computePermissions() resolution engine following
Discord's model: @everyone base → role union → admin shortcut → channel
overrides (role deny/allow → member deny/allow). Ready payload now filters
channels by VIEW_CHANNEL and attaches per-user myPermissions to each
server and channel. Includes channel_overrides table, @everyone role
auto-creation, migration for existing servers, and override CRUD API.
This commit is contained in:
Jannis Braun
2026-02-24 05:08:59 +01:00
parent 024833c470
commit 8030c89c6c
19 changed files with 568 additions and 93 deletions
+11
View File
@@ -0,0 +1,11 @@
// Frontend permission helpers — wraps shared permission constants.
// Always works with string representations (never raw bigint in state).
export {
PermissionBits,
ALL_PERMISSIONS,
DEFAULT_EVERYONE_PERMISSIONS,
hasPermissionBit,
permissionsToString,
stringToPermissions,
} from '@opencord/shared/src/permissions';