Add organizations, team roles, and shared live sessions - #518
Merged
Merged
Conversation
ThreatCrush Security Scan0 finding(s) in the 8 file(s) this pull request changes. Nothing in the files this pull request changes. 97 pre-existing finding(s) elsewhere in the repository — **HIGH/CRITICAL**: 8 | **MEDIUM**: 78 | **LOW**: 11Not introduced by this pull request. The full set is in the Security tab.
…and 77 more. Full results in the Security tab. Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Live terminal sessions were accessible only to their owner. Add organizations, teams, and member roles to app.moshcode.sh so teammates can watch or work in the same running session. Session owners explicitly share a terminal with a team; readers watch, writers send input, and admins/owners manage membership within their scope.
The Teams pages support organization/team creation and adding existing accounts by email, with read access as the default. Membership changes preserve a last owner. Organization administrators inherit team access, while other organization members only see teams they belong to. Equivalent API routes accept CLI Bearer credentials.
Browser commands record their author, and the owner's CLI checks current permissions again when claiming them. Revocation also stops further live output, including output on an already-open stream. CLI output, acknowledgements, and command polling remain owner-only. Existing MCP grants keep their separate scope and revocation checks.
Validation: 3,253 repository tests passed (4 skipped), including all 749 PWA tests. Browser verification covered creating Profullstack/Contractors, read-only viewing on mobile, promoting a teammate to writer, and sending input through the existing CLI command queue. Regression tests cover cross-organization isolation, CSRF/Bearer separation, owner protection, and revocation of both pending input and live output.