From 1bc5fbbf0f0a7e581d6f3748b9381214d0e6e7bc Mon Sep 17 00:00:00 2001 From: Owen Date: Thu, 3 Sep 2026 12:02:41 -0400 Subject: [PATCH] Always pull all of the users for the blueprints --- server/lib/blueprints/findOrgUser.ts | 19 ++++---- server/lib/blueprints/publicResources.ts | 54 ++++++++++++++--------- server/lib/blueprints/resourcePolicies.ts | 46 ++++++++++++------- 3 files changed, 73 insertions(+), 46 deletions(-) diff --git a/server/lib/blueprints/findOrgUser.ts b/server/lib/blueprints/findOrgUser.ts index 1fc054fd1..1b7c1b02a 100644 --- a/server/lib/blueprints/findOrgUser.ts +++ b/server/lib/blueprints/findOrgUser.ts @@ -1,12 +1,12 @@ import { and, asc, eq, or } from "drizzle-orm"; import { Transaction, User, userOrgs, users } from "@server/db"; -export async function findOrgUserByIdentifier( +export async function findOrgUsersByIdentifier( trx: Transaction, orgId: string, identifier: string -): Promise { - const [match] = await trx +): Promise { + const matches = await trx .select() .from(users) .innerJoin(userOrgs, eq(users.userId, userOrgs.userId)) @@ -16,10 +16,9 @@ export async function findOrgUserByIdentifier( eq(userOrgs.orgId, orgId) ) ) - .orderBy(asc(users.dateCreated), asc(users.userId)) - .limit(1); + .orderBy(asc(users.dateCreated), asc(users.userId)); - return match?.user ?? null; + return matches.map((match) => match.user); } export async function resolveOrgUserIds( @@ -29,8 +28,12 @@ export async function resolveOrgUserIds( ): Promise { const userIds = new Set(); for (const identifier of identifiers) { - const user = await findOrgUserByIdentifier(trx, orgId, identifier); - if (user) { + const matchedUsers = await findOrgUsersByIdentifier( + trx, + orgId, + identifier + ); + for (const user of matchedUsers) { userIds.add(user.userId); } } diff --git a/server/lib/blueprints/publicResources.ts b/server/lib/blueprints/publicResources.ts index 7822c2b8a..4bd42ed0b 100644 --- a/server/lib/blueprints/publicResources.ts +++ b/server/lib/blueprints/publicResources.ts @@ -51,7 +51,7 @@ import { tierMatrix } from "../billing/tierMatrix"; import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators"; import { Config, isTargetsOnlyResource, TargetData } from "./types"; import { getOrCreateLabelIds, syncResourceLabels } from "./labels"; -import { findOrgUserByIdentifier } from "./findOrgUser"; +import { findOrgUsersByIdentifier } from "./findOrgUser"; import { LimitId } from "../billing"; import { usageService } from "../billing/usageService"; import { syncInferenceAiConfig } from "./aiProviders"; @@ -1564,21 +1564,27 @@ async function syncUserResources( .where(eq(userResources.resourceId, resourceId)); for (const username of ssoUsers) { - const user = await findOrgUserByIdentifier(trx, orgId, username); + const matchedUsers = await findOrgUsersByIdentifier( + trx, + orgId, + username + ); - if (!user) { + if (matchedUsers.length === 0) { throw new Error(`User not found: ${username} in org ${orgId}`); } - const existingUserResource = existingUserResources.find( - (rr) => rr.userId === user.userId - ); + for (const user of matchedUsers) { + const existingUserResource = existingUserResources.find( + (rr) => rr.userId === user.userId + ); - if (!existingUserResource) { - await trx.insert(userResources).values({ - userId: user.userId, - resourceId: resourceId - }); + if (!existingUserResource) { + await trx.insert(userResources).values({ + userId: user.userId, + resourceId: resourceId + }); + } } } @@ -1946,21 +1952,27 @@ async function syncUserPolicies( .where(eq(userPolicies.resourcePolicyId, policyId)); for (const username of ssoUsers) { - const user = await findOrgUserByIdentifier(trx, orgId, username); + const matchedUsers = await findOrgUsersByIdentifier( + trx, + orgId, + username + ); - if (!user) { + if (matchedUsers.length === 0) { throw new Error(`User not found: ${username} in org ${orgId}`); } - const existingUserPolicy = existingUserPoliciesList.find( - (up) => up.userId === user.userId - ); + for (const user of matchedUsers) { + const existingUserPolicy = existingUserPoliciesList.find( + (up) => up.userId === user.userId + ); - if (!existingUserPolicy) { - await trx.insert(userPolicies).values({ - userId: user.userId, - resourcePolicyId: policyId - }); + if (!existingUserPolicy) { + await trx.insert(userPolicies).values({ + userId: user.userId, + resourcePolicyId: policyId + }); + } } } diff --git a/server/lib/blueprints/resourcePolicies.ts b/server/lib/blueprints/resourcePolicies.ts index 4a883f64b..d8c744cdb 100644 --- a/server/lib/blueprints/resourcePolicies.ts +++ b/server/lib/blueprints/resourcePolicies.ts @@ -22,7 +22,7 @@ import { idpExistsForOrg } from "@server/lib/idp/idpExistsForOrg"; import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators"; import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed"; import { tierMatrix } from "../billing/tierMatrix"; -import { findOrgUserByIdentifier } from "./findOrgUser"; +import { findOrgUsersByIdentifier } from "./findOrgUser"; export type ResourcePoliciesResults = { resourcePolicyId: number; @@ -467,24 +467,30 @@ async function syncUserPolicies( .where(eq(userPolicies.resourcePolicyId, policyId)); for (const username of ssoUsers) { - const user = await findOrgUserByIdentifier(trx, orgId, username); + const matchedUsers = await findOrgUsersByIdentifier( + trx, + orgId, + username + ); - if (!user) { + if (matchedUsers.length === 0) { logger.warn( `User '${username}' not found in org '${orgId}', skipping` ); continue; } - const alreadyExists = existingUserPolicies.some( - (up) => up.userId === user.userId - ); + for (const user of matchedUsers) { + const alreadyExists = existingUserPolicies.some( + (up) => up.userId === user.userId + ); - if (!alreadyExists) { - await trx.insert(userPolicies).values({ - userId: user.userId, - resourcePolicyId: policyId - }); + if (!alreadyExists) { + await trx.insert(userPolicies).values({ + userId: user.userId, + resourcePolicyId: policyId + }); + } } } @@ -527,19 +533,25 @@ async function addUserPolicies( trx: Transaction ) { for (const username of ssoUsers) { - const user = await findOrgUserByIdentifier(trx, orgId, username); + const matchedUsers = await findOrgUsersByIdentifier( + trx, + orgId, + username + ); - if (!user) { + if (matchedUsers.length === 0) { logger.warn( `User '${username}' not found in org '${orgId}', skipping` ); continue; } - await trx.insert(userPolicies).values({ - userId: user.userId, - resourcePolicyId: policyId - }); + for (const user of matchedUsers) { + await trx.insert(userPolicies).values({ + userId: user.userId, + resourcePolicyId: policyId + }); + } } }