Title: feat(access-control): per-group chat-deploy auth modes + polish by waleedlatif1 · Pull Request #5818 · simstudioai/sim · GitHub
Open Graph Title: feat(access-control): per-group chat-deploy auth modes + polish by waleedlatif1 · Pull Request #5818 · simstudioai/sim
X Title: feat(access-control): per-group chat-deploy auth modes + polish by waleedlatif1 · Pull Request #5818 · simstudioai/sim
Description: Summary Add a per-permission-group "Auth modes chat deployments may use" control in the Access Control group's Platform tab, mirroring the existing public-file-share auth-mode control. Admins can now restrict which chat auth modes are allowed (i.e. disable Public, Password, Email, or SSO). Enforced server-side on chat create (POST /api/chat) and update (PATCH /api/chat/manage/[id]) via a new validateChatDeployAuth (throws ChatDeployAuthNotAllowedError → 403), reusing the same getUserPermissionConfig resolver the file-share gate uses. The chat deploy modal's "Access control" options are filtered to the allowed set (the currently-saved mode stays visible so existing state always shows; the route remains the source of truth). Remove the dead Template deploy option (hideDeployTemplate had no consumer anywhere). Shrink the Access Control block permission icons (size-[9px]) so they no longer touch their tile borders, and normalize the tiles to the size-[16px] shorthand. Implementation notes New config field allowedChatDeployAuthTypes (ShareAuthType[] | null, null = all allowed) added to permissionGroupConfigSchema, PermissionGroupConfig, DEFAULT_PERMISSION_GROUP_CONFIG, parsePermissionGroupConfig, and the permissionGroupFullConfigSchema contract. No DB migration — config is a JSONB blob and the parser defaults the field for existing rows. Enforcement mirrors validatePublicFileSharing; no-ops for non-enterprise / access-control-disabled orgs. Type of Change Feature + cleanup Testing Added unit tests for validateChatDeployAuth (allow-list hit/miss, null = all, non-enterprise no-op) and 403 enforcement tests on both chat create and update routes. Full suite: 87 passing. tsc, biome, and check:api-validation all clean. Checklist Code follows project style guidelines Self-reviewed my changes Tests added/updated and passing No new warnings introduced I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)
Open Graph Description: Summary Add a per-permission-group "Auth modes chat deployments may use" control in the Access Control group's Platform tab, mirroring the existing public-file-share auth-mode contro...
X Description: Summary Add a per-permission-group "Auth modes chat deployments may use" control in the Access Control group's Platform tab, mirroring the existing public-file-share auth...
Opengraph URL: https://github.com/simstudioai/sim/pull/5818
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:526b0e05-977a-54eb-de7c-b9152f426078 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | D6D8:304E54:415D6B:5BE77A:6A637B59 |
| html-safe-nonce | 10eb26712c16883fddf3913dc3628b32f3c0c9180612cffcb7507e1308753a55 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJENkQ4OjMwNEU1NDo0MTVENkI6NUJFNzdBOjZBNjM3QjU5IiwidmlzaXRvcl9pZCI6IjEwODM1Mjc3OTI4MDQ3MjM1NDUiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 5203fdecc00bc18c636e14374f46f1fb0471d6974519f61cdf14b87bcf1ab579 |
| hovercard-subject-tag | pull_request:4103222987 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/simstudioai/sim/pull/5818/files |
| twitter:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| og:image:alt | Summary Add a per-permission-group "Auth modes chat deployments may use" control in the Access Control group's Platform tab, mirroring the existing public-file-share auth-mode contro... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 4c1de337de00c7969335f8866af41463301071379a3a15fba12e9b85aa6378d6 |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/simstudioai/sim git https://github.com/simstudioai/sim.git |
| octolytics-dimension-user_id | 199344406 |
| octolytics-dimension-user_login | simstudioai |
| octolytics-dimension-repository_id | 912559512 |
| octolytics-dimension-repository_nwo | simstudioai/sim |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 912559512 |
| octolytics-dimension-repository_network_root_nwo | simstudioai/sim |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | a4df32552e4c631011bdcd4c81cc3d7408664a8b |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width