diff --git a/services/web/app/src/Features/Authorization/PermissionsManager.js b/services/web/app/src/Features/Authorization/PermissionsManager.js index 1f7bfb99b8..9bf076364e 100644 --- a/services/web/app/src/Features/Authorization/PermissionsManager.js +++ b/services/web/app/src/Features/Authorization/PermissionsManager.js @@ -133,8 +133,16 @@ function registerPolicy(name, capabilities, options = {}) { * @returns {Array} An array of policy names that are enforced. */ function getEnforcedPolicyNames(groupPolicy = {}) { - return Object.keys(groupPolicy).filter( - policyName => groupPolicy[policyName] !== false + if (!groupPolicy) { + return [] + } + return Object.keys( + typeof groupPolicy.toObject === 'function' + ? groupPolicy.toObject() + : groupPolicy + ).filter( + policyName => + !['__v', '_id'].includes(policyName) && groupPolicy[policyName] !== false ) // filter out the policies that are not enforced } diff --git a/services/web/app/src/Features/Project/ProjectListController.js b/services/web/app/src/Features/Project/ProjectListController.js index 8dfcf2c226..0981ed58ef 100644 --- a/services/web/app/src/Features/Project/ProjectListController.js +++ b/services/web/app/src/Features/Project/ProjectListController.js @@ -32,7 +32,6 @@ const SplitTestHandler = require('../SplitTests/SplitTestHandler') /** @typedef {import("../../../../types/project/dashboard/api").Sort} Sort */ /** @typedef {import("./types").AllUsersProjects} AllUsersProjects */ /** @typedef {import("./types").MongoProject} MongoProject */ - /** @typedef {import("../Tags/types").Tag} Tag */ const _ssoAvailable = (affiliation, session, linkedInstitutionIds) => { @@ -90,6 +89,10 @@ async function projectListPage(req, res, next) { // - object - the subscription data object let usersBestSubscription let survey + let userIsMemberOfGroupSubscription = false + let groupSubscriptionsPendingEnrollment = [] + + const isSaas = Features.hasFeature('saas') const userId = SessionManager.getLoggedInUserId(req.session) const projectsBlobPending = _getProjects(userId).catch(err => { @@ -98,7 +101,9 @@ async function projectListPage(req, res, next) { }) const user = await User.findById( userId, - 'email emails features lastPrimaryEmailCheck signUpDate' + `email emails features lastPrimaryEmailCheck signUpDate${ + isSaas ? ' enrollment' : '' + }` ) // Handle case of deleted user @@ -107,7 +112,7 @@ async function projectListPage(req, res, next) { return } - if (Features.hasFeature('saas')) { + if (isSaas) { try { usersBestSubscription = await SubscriptionViewModelBuilder.promises.getBestSubscription({ @@ -119,6 +124,24 @@ async function projectListPage(req, res, next) { "Failed to get user's best subscription" ) } + try { + const { isMember, subscriptions } = + await LimitationsManager.promises.userIsMemberOfGroupSubscription(user) + + userIsMemberOfGroupSubscription = isMember + + // TODO use helper function + if (!user.enrollment?.managedBy) { + groupSubscriptionsPendingEnrollment = subscriptions.filter( + subscription => subscription.groupPlan && subscription.groupPolicy + ) + } + } catch (error) { + logger.error( + { err: error }, + 'Failed to check whether user is a member of group subscription' + ) + } try { survey = await SurveyHandler.promises.getSurvey(userId) @@ -280,20 +303,6 @@ async function projectListPage(req, res, next) { status: prefetchedProjectsBlob ? 'success' : 'too-slow', }) - let userIsMemberOfGroupSubscription = false - try { - const userIsMemberOfGroupSubscriptionPromise = - await LimitationsManager.promises.userIsMemberOfGroupSubscription(user) - - userIsMemberOfGroupSubscription = - userIsMemberOfGroupSubscriptionPromise.isMember - } catch (error) { - logger.error( - { err: error }, - 'Failed to check whether user is a member of group subscription' - ) - } - // in v2 add notifications for matching university IPs if (Settings.overleaf != null && req.ip !== user.lastLoginIp) { try { @@ -395,6 +404,11 @@ async function projectListPage(req, res, next) { showINRBanner, projectDashboardReact: true, // used in navbar welcomePageRedesignVariant: welcomePageRedesignAssignment.variant, + groupSubscriptionsPendingEnrollment: + groupSubscriptionsPendingEnrollment.map(subscription => ({ + groupId: subscription._id, + groupName: subscription.teamName, + })), }) } diff --git a/services/web/app/src/Features/User/UserPagesController.js b/services/web/app/src/Features/User/UserPagesController.js index db91812cb4..56cf51ad76 100644 --- a/services/web/app/src/Features/User/UserPagesController.js +++ b/services/web/app/src/Features/User/UserPagesController.js @@ -126,6 +126,7 @@ async function settingsPage(req, res) { showPersonalAccessToken, personalAccessTokens, emailAddressLimit: Settings.emailAddressLimit, + isManagedAccount: !!user.enrollment?.managedBy, }) } diff --git a/services/web/app/src/Features/UserMembership/UserMembershipAuthorization.js b/services/web/app/src/Features/UserMembership/UserMembershipAuthorization.js index e7cd9caccf..e3c29d32d6 100644 --- a/services/web/app/src/Features/UserMembership/UserMembershipAuthorization.js +++ b/services/web/app/src/Features/UserMembership/UserMembershipAuthorization.js @@ -22,5 +22,16 @@ const UserMembershipAuthorization = { ) } }, + + isEntityMember() { + return req => { + if (!req.entity) { + return false + } + return req.entity[req.entityConfig.fields.membership].some(accessUserId => + accessUserId.equals(req.user._id) + ) + } + }, } module.exports = UserMembershipAuthorization diff --git a/services/web/app/src/Features/UserMembership/UserMembershipEntityConfigs.js b/services/web/app/src/Features/UserMembership/UserMembershipEntityConfigs.js index 7549049a9d..94bc01f7f2 100644 --- a/services/web/app/src/Features/UserMembership/UserMembershipEntityConfigs.js +++ b/services/web/app/src/Features/UserMembership/UserMembershipEntityConfigs.js @@ -8,6 +8,7 @@ module.exports = { read: ['invited_emails', 'teamInvites', 'member_ids'], write: null, access: 'manager_ids', + membership: 'member_ids', name: 'teamName', }, baseQuery: { @@ -47,6 +48,7 @@ module.exports = { read: ['manager_ids'], write: 'manager_ids', access: 'manager_ids', + membership: 'member_ids', name: 'teamName', }, baseQuery: { @@ -72,6 +74,7 @@ module.exports = { read: ['managerIds'], write: 'managerIds', access: 'managerIds', + membership: 'member_ids', name: 'name', }, translations: { @@ -95,6 +98,7 @@ module.exports = { read: ['managerIds'], write: 'managerIds', access: 'managerIds', + membership: 'member_ids', name: 'name', }, translations: { diff --git a/services/web/app/src/Features/UserMembership/UserMembershipMiddleware.js b/services/web/app/src/Features/UserMembership/UserMembershipMiddleware.js index e80c4e8757..fc443cf67a 100644 --- a/services/web/app/src/Features/UserMembership/UserMembershipMiddleware.js +++ b/services/web/app/src/Features/UserMembership/UserMembershipMiddleware.js @@ -22,6 +22,15 @@ const UserMembershipMiddleware = { ]), ], + requireGroup: [fetchEntityConfig('group'), fetchEntity(), requireEntity()], + + requireGroupAccess: [ + AuthenticationController.requireLogin(), + fetchEntityConfig('group'), + fetchEntity(), + requireEntity(), + ], + requireGroupManagementAccess: [ AuthenticationController.requireLogin(), fetchEntityConfig('group'), diff --git a/services/web/app/views/project/list-react.pug b/services/web/app/views/project/list-react.pug index 3cd9f7f250..f3d8565cd3 100644 --- a/services/web/app/views/project/list-react.pug +++ b/services/web/app/views/project/list-react.pug @@ -30,6 +30,7 @@ block append meta meta(name="ol-groupsAndEnterpriseBannerVariant" data-type="string" content=groupsAndEnterpriseBannerVariant) meta(name="ol-showINRBanner" data-type="boolean" content=showINRBanner) meta(name="ol-welcomePageRedesignVariant" data-type="string" content=welcomePageRedesignVariant) + meta(name="ol-groupSubscriptionsPendingEnrollment" data-type="json" content=groupSubscriptionsPendingEnrollment) block content main.content.content-alt.project-list-react#project-list-root diff --git a/services/web/app/views/user/settings.pug b/services/web/app/views/user/settings.pug index a6c265c05e..e29f0d2184 100644 --- a/services/web/app/views/user/settings.pug +++ b/services/web/app/views/user/settings.pug @@ -25,6 +25,7 @@ block append meta meta(name="ol-showPersonalAccessToken", data-type="boolean" content=showPersonalAccessToken) meta(name="ol-personalAccessTokens", data-type="json" content=personalAccessTokens) meta(name="ol-emailAddressLimit", data-type="json", content=emailAddressLimit) + meta(name="ol-isManagedAccount" data-type="boolean" content=isManagedAccount) block content main.content.content-alt#settings-page-root diff --git a/services/web/config/settings.defaults.js b/services/web/config/settings.defaults.js index d9a6916f9a..80c39035f0 100644 --- a/services/web/config/settings.defaults.js +++ b/services/web/config/settings.defaults.js @@ -808,6 +808,7 @@ module.exports = { editorLeftMenuSync: [], editorLeftMenuManageTemplate: [], oauth2Server: [], + managedGroupSubscriptionEnrollmentNotification: [], }, moduleImportSequence: ['launchpad', 'server-ce-scripts', 'user-activate'], diff --git a/services/web/frontend/extracted-translations.json b/services/web/frontend/extracted-translations.json index 52229c81c9..8410af827e 100644 --- a/services/web/frontend/extracted-translations.json +++ b/services/web/frontend/extracted-translations.json @@ -14,10 +14,12 @@ "about_to_leave_projects": "", "about_to_trash_projects": "", "accept": "", + "accept_invitation": "", "accepted_invite": "", "access_denied": "", "account_has_been_link_to_institution_account": "", "account_has_past_due_invoice_change_plan_warning": "", + "account_managed_by_group_administrator": "", "account_not_linked_to_dropbox": "", "account_settings": "", "acct_linked_to_institution_acct_2": "", @@ -117,6 +119,7 @@ "change_plan": "", "change_primary_email_address_instructions": "", "change_project_owner": "", + "change_the_ownership_of_your_personal_projects": "", "change_to_group_plan": "", "change_to_this_plan": "", "changing_the_position_of_your_figure": "", @@ -220,6 +223,7 @@ "discount_of": "", "dismiss": "", "dismiss_error_popup": "", + "do_this_later": "", "do_you_want_to_change_your_primary_email_address_to": "", "do_you_want_to_overwrite_them": "", "documentation": "", @@ -403,6 +407,8 @@ "go_to_pdf_location_in_code": "", "go_to_settings": "", "group_admin": "", + "group_admin_or_managers_can_reassign_projects": "", + "group_managed_by_group_administrator": "", "group_plan_tooltip": "", "group_plan_with_name_tooltip": "", "group_subscription": "", @@ -506,6 +512,7 @@ "join_project": "", "joining": "", "keep_current_plan": "", + "keep_personal_projects_separate": "", "keybindings": "", "labels_help_you_to_easily_reference_your_figures": "", "labs_program_already_participating": "", @@ -525,6 +532,7 @@ "learn_more": "", "learn_more_about_link_sharing": "", "leave": "", + "leave_any_group_subscriptions": "", "leave_group": "", "leave_now": "", "leave_projects": "", @@ -560,6 +568,7 @@ "log_hint_extra_info": "", "log_in_with_primary_email_address": "", "log_viewer_error": "", + "login_to_transfer_account": "", "login_with_service": "", "login_with_service_will_stop_working_soon": "", "logs_and_output_files": "", @@ -616,6 +625,8 @@ "navigate_log_source": "", "navigation": "", "need_anything_contact_us_at": "", + "need_contact_group_admin_to_make_changes": "", + "need_make_changes": "", "need_more_than_x_licenses": "", "need_to_add_new_primary_before_remove": "", "need_to_leave": "", @@ -667,6 +678,7 @@ "ok": "", "on": "", "on_free_plan_upgrade_to_access_features": "", + "only_group_admin_or_managers_can_delete_your_account": "", "open_project": "", "optional": "", "or": "", @@ -804,6 +816,7 @@ "remove_from_group": "", "remove_manager": "", "remove_or_replace_figure": "", + "remove_secondary_email_addresses": "", "remove_tag": "", "removing": "", "rename": "", @@ -896,6 +909,7 @@ "session_expired_redirecting_to_login": "", "sessions": "", "settings": "", + "setup_another_account_under_a_personal_email_address": "", "share": "", "share_project": "", "share_with_your_collabs": "", @@ -999,6 +1013,7 @@ "to_add_email_accounts_need_to_be_linked_2": "", "to_add_more_collaborators": "", "to_change_access_permissions": "", + "to_confirm_transfer_enter_email_address": "", "to_modify_your_subscription_go_to": "", "toggle_compile_options_menu": "", "token": "", @@ -1040,6 +1055,11 @@ "track_changes_is_on": "", "tracked_change_added": "", "tracked_change_deleted": "", + "transfer_account": "", + "transfer_management_of_your_account": "", + "transfer_management_of_your_account_to_x": "", + "transfer_management_resolve_following_issues": "", + "transferring": "", "trash": "", "trash_projects": "", "trashed": "", @@ -1072,6 +1092,8 @@ "unlink_dropbox_warning": "", "unlink_github_repository": "", "unlink_github_warning": "", + "unlink_linked_accounts": "", + "unlink_linked_google_account": "", "unlink_provider_account_title": "", "unlink_provider_account_warning": "", "unlink_reference": "", @@ -1123,6 +1145,7 @@ "we_logged_you_in": "", "wed_love_you_to_stay": "", "welcome_to_sl": "", + "what_does_this_mean_for_you": "", "when_you_tick_the_include_caption_box": "", "wide": "", "with_premium_subscription_you_also_get": "", @@ -1150,6 +1173,8 @@ "you_can_now_log_in_sso": "", "you_dont_have_any_repositories": "", "you_have_added_x_of_group_size_y": "", + "you_have_been_invited_to_transfer_management_of_your_account": "", + "you_have_been_invited_to_transfer_management_of_your_account_to": "", "your_affiliation_is_confirmed": "", "your_browser_does_not_support_this_feature": "", "your_git_access_info": "", diff --git a/services/web/frontend/js/features/project-list/components/notifications/user-notifications.tsx b/services/web/frontend/js/features/project-list/components/notifications/user-notifications.tsx index 5749ad02e0..3bd9da76d4 100644 --- a/services/web/frontend/js/features/project-list/components/notifications/user-notifications.tsx +++ b/services/web/frontend/js/features/project-list/components/notifications/user-notifications.tsx @@ -1,3 +1,4 @@ +import { JSXElementConstructor } from 'react' import Common from './groups/common' import Institution from './groups/institution' import ConfirmEmail from './groups/confirm-email' @@ -6,13 +7,39 @@ import GroupsAndEnterpriseBanner from './groups-and-enterprise-banner' import WritefullPromoBanner from './writefull-promo-banner' import INRBanner from './ads/inr-banner' import getMeta from '../../../../utils/meta' +import importOverleafModules from '../../../../../macros/import-overleaf-module.macro' + +type Subscription = { + groupId: string + groupName: string +} + +const [enrollmentNotificationModule] = importOverleafModules( + 'managedGroupSubscriptionEnrollmentNotification' +) +const EnrollmentNotification: JSXElementConstructor<{ + groupId: string + groupName: string +}> = enrollmentNotificationModule?.import.default function UserNotifications() { - const showIRNBanner = getMeta('ol-showINRBanner') + const showIRNBanner = getMeta('ol-showINRBanner', false) + const groupSubscriptionsPendingEnrollment: Subscription[] = getMeta( + 'ol-groupSubscriptionsPendingEnrollment', + [] + ) return (