Skip to content

Staff role access (admin except bot invite) - #16

Merged
wraithfive merged 5 commits into
masterfrom
feat/staff-role-permissions
Jan 18, 2026
Merged

wraithfive merged 5 commits into
masterfrom
feat/staff-role-permissions

Conversation

@wraithfive

Copy link
Copy Markdown
Owner

Summary

  • Allow Staff role to manage everything admins can, except bot invite
  • Keep bot invite restricted to actual admins (ADMINISTRATOR or MANAGE_SERVER)
  • Add Staff-aware checks in admin service and controller
  • Add tests for Staff role access, admin-only invites, and negative cases

Testing

  • ./build.sh
  • Added new unit tests in AdminServiceBranchesTest and ServerControllerTest

Notes

  • Maintains admin-only bot invite; Staff cannot invite the bot
  • No schema changes; logic only

- Treat Staff role as admin-equivalent for server management, but keep bot invites admin-only
- Add actual admin check for invites and staff-aware admin checks elsewhere
- Add tests covering Staff role access, admin-only invites, and no-access cases
@wraithfive
wraithfive marked this pull request as ready for review January 18, 2026 15:59
Copilot AI review requested due to automatic review settings January 18, 2026 15:59
@wraithfive
wraithfive marked this pull request as draft January 18, 2026 16:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request introduces a new "Staff" role that grants users access to most admin functions except bot invitations. The change adds a distinction between general admin access (including Staff role holders) and actual Discord admin permissions (ADMINISTRATOR or MANAGE_SERVER only).

Changes:

  • Modified isUserAdminInGuild to check for Staff role when Discord admin permissions are absent
  • Added isUserActualAdminInGuild method to verify actual Discord admin permissions without Staff role consideration
  • Updated bot invite endpoint to use the stricter admin check, keeping bot invitations restricted to actual admins

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.

File Description
src/main/java/com/discordbot/web/service/AdminService.java Added Staff role checking logic with new hasStaffRole helper method and isUserActualAdminInGuild method for restricted operations
src/main/java/com/discordbot/web/controller/ServerController.java Updated bot invite endpoint to use stricter isUserActualAdminInGuild check instead of general admin check
src/test/java/com/discordbot/ServerControllerTest.java Updated bot invite tests to use the new isUserActualAdminInGuild method
src/test/java/com/discordbot/AdminServiceBranchesTest.java Added comprehensive tests for Staff role behavior, actual admin checks, and negative cases

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/test/java/com/discordbot/AdminServiceBranchesTest.java
Comment thread src/main/java/com/discordbot/web/service/AdminService.java Outdated
Comment thread src/main/java/com/discordbot/web/service/AdminService.java Outdated

@wraithfive wraithfive left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed feedback: added Staff-role mocks to the negative actual-admin test, added a parse-guard test for non-numeric permissions, and hardened permission parsing with primitive long + null/format handling.

Comment thread src/test/java/com/discordbot/AdminServiceBranchesTest.java
Comment thread src/main/java/com/discordbot/web/service/AdminService.java Outdated
Comment thread src/main/java/com/discordbot/web/service/AdminService.java Outdated
Repository owner deleted a comment from Copilot AI Jan 18, 2026
@wraithfive
wraithfive marked this pull request as ready for review January 18, 2026 16:17
@wraithfive
wraithfive requested a review from Copilot January 18, 2026 16:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 4 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

* Check if user has actual ADMINISTRATOR or MANAGE_SERVER permissions (no Staff role)
* Use this for restricted actions like bot invites
*/
public boolean isUserActualAdminInGuild(Authentication authentication, String guildId) {

Copilot AI Jan 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The naming of isUserActualAdminInGuild could be clearer. The term "actual" is somewhat ambiguous - it might be more explicit to name this method something like hasDiscordAdminPermissions or isUserDiscordAdminInGuild to clearly indicate that it only checks Discord permissions and excludes role-based access.

Copilot uses AI. Check for mistakes.
}

return member.getRoles().stream()
.anyMatch(role -> role.getName().equalsIgnoreCase("Staff"));

Copilot AI Jan 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The documentation mentions the "Staff" role specifically (with capital S), but the implementation uses case-insensitive matching via equalsIgnoreCase("Staff"). Consider documenting this case-insensitive behavior in the README.md and SECURITY.md, or alternatively, use exact case matching if the role name should be case-sensitive.

Suggested change
.anyMatch(role -> role.getName().equalsIgnoreCase("Staff"));
.anyMatch(role -> role.getName().equals("Staff"));

Copilot uses AI. Check for mistakes.
Comment thread src/main/java/com/discordbot/web/service/AdminService.java Outdated
Comment thread src/main/java/com/discordbot/web/service/AdminService.java
@wraithfive
wraithfive merged commit 4d1bb37 into master Jan 18, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants