Skip to content

feat(teams): org-enforced lock policy (#510) - #101

Merged
kipavy merged 3 commits into
mainfrom
feat/org-lock-policy
Oct 8, 2026
Merged

kipavy merged 3 commits into
mainfrom
feat/org-lock-policy

Conversation

@kipavy

@kipavy kipavy commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Server half of the org-enforced lock policy (VoltiusApp/voltius#510, spec 3).

What it adds

  • Migration 057_team_lock_policy.sql: teams.lock_max_minutes INT NULL (NULL = no policy) and teams.lock_force_vault BOOL NOT NULL DEFAULT false.
  • PUT /v1/teams/:team_id/lock-policy with {max_minutes, force_vault} and DELETE on the same path, both 204.
    • max_minutes must be one of 0, 5, 15, 30, 60, 240 (0 = Immediately), else 400.
    • Needs MANAGE_VAULT or ADMINISTRATOR, the same check as renaming the team (extracted into require_vault_manager, which rename_team now uses too).
    • Writes a team.lock_policy_set / team.lock_policy_removed audit event and notifies every member (team_members:<id>).
  • GET /v1/teams rows gain lock_policy: null | {max_minutes, force_vault}.

Plan gate

Business only, through require_granular: below Business a PUT returns 402 and a DELETE still works, so an existing policy stays enforced until an admin removes it. Self-hosted counts as Business.

Compatibility and rollback

  • Older clients ignore lock_policy and don't enforce it; the client PR says so in its admin panel.
  • The migration only adds columns. Rolling back is setting SERVER_TAG to the previous image; the extra columns are inert.
  • Deploy this before releasing the client.

Tests

cargo test --bin voltius-server: 692 passed (rebased on main 1f952b3) (7 new in routes::team_lock_policy). cargo clippy --all-targets -- -D warnings clean.

@kipavy
kipavy force-pushed the feat/org-lock-policy branch from 3b6c720 to bf0ea27 Compare October 8, 2026 14:10
@kipavy
kipavy merged commit ff7968c into main Oct 8, 2026
1 check passed
@kipavy
kipavy deleted the feat/org-lock-policy branch October 9, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant