You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This pull request adds support for transferring container ownership from the frontend UI and backend API, allowing an owner or admin to hand a container to another active user. It includes UI components, backend logic, API documentation updates, and comprehensive tests to ensure correct behavior and access control. The most important changes are grouped below.
Frontend: Ownership Transfer UI
Added a new TransferOwnership component to the container edit page, allowing owners and admins to transfer ownership to another user; this includes confirmation dialogs and error handling. [1][2][3]
Backend: API and Logic
Updated the PUT /api/v1/sites/:siteId/containers/:id endpoint to allow ownership transfer by owner or admin, with validation for user existence and activity, and logic to move resource requests and remove sharing grants. [1][2][3][4][5]
Added a new query method in queries.ts for initiating ownership transfer from the frontend.
Testing
Added comprehensive backend tests for ownership transfer, covering success, permission checks, user validation, resource migration, and sharing grant removal.
Documentation and API Contract
Updated OpenAPI spec to document ownership transfer, error cases, and clarify permissions and side effects. [1][2]
Added user documentation describing ownership transfer, its effects, and the API usage.Allow container owners and admins to transfer ownership to another active user from the edit page. The API now validates transfer targets, removes any collaborator grant for the new owner, moves resource requests to the new owner, and returns clearer ownership-specific responses. Also adds UI support, API docs updates, admin docs, and coverage for owner/admin/collaborator transfer behavior.
Allow container owners and admins to transfer ownership to another active user from the edit page. The API now validates transfer targets, removes any collaborator grant for the new owner, moves resource requests to the new owner, and returns clearer ownership-specific responses. Also adds UI support, API docs updates, admin docs, and coverage for owner/admin/collaborator transfer behavior.
The reason will be displayed to describe this comment to others. Learn more.
Made a commit 83a6ea3 container ownership reassignment is now admin-only across the API, UI, tests, OpenAPI spec, and admin docs. The ownership transfer card now only appears for admins, non-admin transfer attempts return 403, and related messaging/docs were updated to reflect that previous owners lose access after a transfer.
Make container ownership reassignment admin-only across the API, UI, tests, OpenAPI spec, and admin docs. The ownership transfer card now only appears for admins, non-admin transfer attempts return 403, and related messaging/docs were updated to reflect that previous owners lose access after a transfer.
The PR description promises ownership transfer for both the current owner and admins, but this check rejects every non-admin owner; the UI also hides the control from owners. Either authorize the current owner and expose the control to owner/admin sessions, or update the PR contract to state that transfers are admin-only.
Confirmation misstates access revocation and volume movement
The confirmation incorrectly says the previous owner loses access, although ldapusers retain SSH access to every container. Distinguish management/UI access from cluster-wide SSH access so admins do not treat this operation as access revocation; also avoid saying the volume data physically moves because its host path remains fixed.
Ownership transfer does not revoke cluster-wide SSH access
“Loses access” is inaccurate: this page already states that every ldapusers member can SSH into any container. Ownership transfer removes management and UI/API visibility, but it does not revoke cluster-wide SSH access, so the current wording can create a false security expectation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request adds support for transferring container ownership from the frontend UI and backend API, allowing an owner or admin to hand a container to another active user. It includes UI components, backend logic, API documentation updates, and comprehensive tests to ensure correct behavior and access control. The most important changes are grouped below.
Frontend: Ownership Transfer UI
TransferOwnershipcomponent to the container edit page, allowing owners and admins to transfer ownership to another user; this includes confirmation dialogs and error handling. [1] [2] [3]Backend: API and Logic
PUT /api/v1/sites/:siteId/containers/:idendpoint to allow ownership transfer by owner or admin, with validation for user existence and activity, and logic to move resource requests and remove sharing grants. [1] [2] [3] [4] [5]queries.tsfor initiating ownership transfer from the frontend.Testing
Documentation and API Contract