2026.10.14 — 2026-10-06
Breaking
Add the caller's access summary, an access check, and lookups for team admins (b49fe99d)
GET /api/v1/me/accesstells the signed-in user what they hold: globally, or on one cluster with?clusterId=. It lists the permissions they hold through role grants at global, environment or cluster scope, the resource permissions they hold on some queue or address of the cluster through a team or share, and whether they can see the cluster. It also lists their teams and their role in each, marking the roles that holdteam:admin.GET /api/v1/users/{id}/access-check?clusterId&kind&name(needsuser:admin) lists every catalogue permission for that user, whether they hold it there, and each way they do: a role granted at a scope, a team role on the team that owns the queue or address, or a share from the owning team.- A team admin, in a team or globally, can now look up enabled users by name prefix (
GET /api/v1/teams/lookups/users?q=, at most 20) and list the team roles with their permissions (GET /api/v1/teams/lookups/roles), withoutuser:admin.user:adminkeeps the full user and role endpoints. - The team list now carries each team's patterns with their cluster and kind.
Added
Let team admins pick members from lookups, and check a user's access (8fa06fec)
- Team admins can add members by searching enabled users by name and choosing from the team roles, without
user:admin; Shares uses the same role list. - The Teams list shows each team's patterns with their cluster and kind.
- "Assign to this team" on an unowned queue or address asks whether the pattern covers queues, addresses or both before pre-filling the pattern form.
- "Effective permissions" in Users is now "Access check": choose a cluster, and a queue or address on it, to see every permission with whether the user holds it there and each role, team or share that gives it. The roles the user holds stay below it.
- Team admins can add members by searching enabled users by name and choosing from the team roles, without
Add the caller's access summary, an access check, and lookups for team admins (b49fe99d)
GET /api/v1/me/accesstells the signed-in user what they hold: globally, or on one cluster with?clusterId=. It lists the permissions they hold through role grants at global, environment or cluster scope, the resource permissions they hold on some queue or address of the cluster through a team or share, and whether they can see the cluster. It also lists their teams and their role in each, marking the roles that holdteam:admin.GET /api/v1/users/{id}/access-check?clusterId&kind&name(needsuser:admin) lists every catalogue permission for that user, whether they hold it there, and each way they do: a role granted at a scope, a team role on the team that owns the queue or address, or a share from the owning team.- A team admin, in a team or globally, can now look up enabled users by name prefix (
GET /api/v1/teams/lookups/users?q=, at most 20) and list the team roles with their permissions (GET /api/v1/teams/lookups/roles), withoutuser:admin.user:adminkeeps the full user and role endpoints. - The team list now carries each team's patterns with their cluster and kind.
Manage teams, their patterns, members and shares (71a975d1)
Administration has a Teams tab. It lists each team with its member, pattern and share counts, and lets an administrator create, rename and delete teams (delete states what goes with the team and asks for its name). Opening a team puts it in the address, with its own sections:
- Patterns: add a pattern for a cluster, a kind (queues, addresses or both) and a name pattern. While you type, the page shows how many queues and addresses it matches now, with examples, and names the other team and pattern as an inline error when it would overlap. Removing a pattern states how many resources it matches before it can be armed.
- Members: users and directory groups with their team role, which can be changed in place or removed. Only team roles are offered. A team admin without user:admin can change user members; directory groups are shown disabled with the reason.
- Shares: what the team shares with others and what others share with it, with a "Not covered" mark on a share whose pattern the owner no longer contains.
- Unowned: the queues or addresses of a cluster that no team owns, each with an "Assign to this team" action that pre-fills the pattern form with its name.
A team admin sees their own teams, with patterns and shares read-only and the reason stated. The user menu offers Administration to a team admin too.
Mark team roles and add required permissions in the role editor (643429cf)
The role editor has a Team role switch. A team role is one that can be given to a team's members or in a share; the permission picker then offers only permissions that act on a queue or address, plus team:admin, and lists anything else the role holds, with a button to remove it. Built-in roles show whether they are team roles, and the roles table has a Team role column.
Each permission shows where it takes effect (Global, Cluster, or Resource with the kinds it acts on), replacing the old "Global only" badge.
Choosing a permission now adds the permissions it requires, with a note ("Added queue:read, required by queue:purge"). Removing a permission that others require asks first and removes them too.
Grant roles per environment or cluster (2ccc0186)
Granting a role to a user, and mapping an identity provider group to a role, now asks where the role applies: everywhere, in one environment, or on one cluster. Before, the console always granted globally and told you to use the API for anything narrower.
Each grant in the Users table, and each group mapping, now shows its scope in words, naming the environment or cluster ("VIEWER (Cluster prod)").
Fixed
Decide what to offer from the server's access summary (16b16ba9)
Which controls the console offers now comes from
/api/v1/me/access, computed by the same resolver that enforces, instead of from the grants of/auth/meevaluated in the browser. That fixes grants given on an environment, which the browser could not see, so their holders were shown disabled controls they were allowed to use. Someone who holdsteam:adminonly through a team is now offered the team administration they may do. While a cluster's answer has not arrived the control is offered, as it is while grants load.
Security
Look users up only by a two-letter prefix, without their provider (9b22b303)
A team admin's user lookup returned the first twenty accounts for an empty prefix, so walking short prefixes listed every enabled username together with its identity provider. The lookup now answers only a prefix of two characters or more and returns the id and username; usernames are already unique across providers.