fix: list shared projects (owned ∪ shared) in Web UI project list (#2)

The Projects page filtered with eq(projects.userId, userId), so a user
with an rw (or ro) share on someone else's project never saw it in the
list — even though project.identify already returned {shared, access}
for the same project. Switch to getAccessibleProjects(userId,
groupNames) (owner ∪ group-shared, the same helper search/memories use)
and aggregate counts over that id set, and label non-owned rows with a
'shared · ro|rw' badge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-12 11:38:22 -07:00
co-authored by Claude Opus 4.8
parent 30194463b5
commit 86433afe1f
+20 -3
View File
@@ -1,8 +1,9 @@
import Link from "next/link"; import Link from "next/link";
import { and, desc, eq, isNull, sql } from "drizzle-orm"; import { and, desc, eq, inArray, isNull, sql } from "drizzle-orm";
import { auth } from "@/auth"; import { auth } from "@/auth";
import { db } from "@/lib/db/client"; import { db } from "@/lib/db/client";
import { memories, projects } from "@/lib/db/schema"; import { memories, projects } from "@/lib/db/schema";
import { getAccessibleProjects, getUserGroupNames } from "@/lib/access";
import { Container, PageHeader } from "@/app/_components/ui/container"; import { Container, PageHeader } from "@/app/_components/ui/container";
import { Card } from "@/app/_components/ui/card"; import { Card } from "@/app/_components/ui/card";
import { Badge } from "@/app/_components/ui/badge"; import { Badge } from "@/app/_components/ui/badge";
@@ -13,8 +14,21 @@ export const dynamic = "force-dynamic";
export default async function ProjectsPage() { export default async function ProjectsPage() {
const session = await auth(); const session = await auth();
const userId = session!.user.id; const userId = session!.user.id;
const groupNames = await getUserGroupNames(userId);
const rows = await db // The project list is owned shared: projects the user owns PLUS
// projects shared with one of their groups (any access). Visibility was
// previously owner-only (`eq(projects.userId, userId)`), which hid
// projects another user shared in via project_shares even though
// project.identify already reported them as {shared, access}.
const accessible = await getAccessibleProjects(userId, groupNames);
const accessById = new Map(accessible.map((p) => [p.projectId, p.access]));
const accessibleIds = accessible.map((p) => p.projectId);
const rows =
accessibleIds.length === 0
? []
: await db
.select({ .select({
id: projects.id, id: projects.id,
key: projects.key, key: projects.key,
@@ -28,7 +42,7 @@ export default async function ProjectsPage() {
memories, memories,
and(eq(memories.projectId, projects.id), isNull(memories.deletedAt)), and(eq(memories.projectId, projects.id), isNull(memories.deletedAt)),
) )
.where(eq(projects.userId, userId)) .where(inArray(projects.id, accessibleIds))
.groupBy(projects.id) .groupBy(projects.id)
.orderBy(desc(sql`max(${memories.createdAt})`)); .orderBy(desc(sql`max(${memories.createdAt})`));
@@ -57,6 +71,9 @@ export default async function ProjectsPage() {
<div className="flex items-center gap-2"> <div className="flex items-center gap-2">
<span className="font-mono text-sm text-fg truncate">{p.key}</span> <span className="font-mono text-sm text-fg truncate">{p.key}</span>
<Badge>{p.memoryCount}</Badge> <Badge>{p.memoryCount}</Badge>
{accessById.get(p.id) !== "owner" ? (
<Badge tone="accent">shared · {accessById.get(p.id)}</Badge>
) : null}
</div> </div>
{p.displayName && p.displayName !== p.key ? ( {p.displayName && p.displayName !== p.key ? (
<div className="text-xs text-fg-muted truncate mt-0.5">{p.displayName}</div> <div className="text-xs text-fg-muted truncate mt-0.5">{p.displayName}</div>