@@ -17,10 +17,10 @@ import type { CloudflareConfig } from "../config";
1717// uses), reading the `Cf-Access-Jwt-Assertion` header off the request.
1818//
1919// Single-tenant + Access-managed: members, roles, and API keys live in
20- // Cloudflare Access, NOT in the app. The shell hides the API-keys footer and
21- // shows no members page, so those methods are never reached from the UI; they
22- // return empty (reads) or a clear "managed by Cloudflare Access" error (writes)
23- // to satisfy the provider shape .
20+ // Cloudflare Access, NOT in the app. Writes stay refused. `listMembers` still
21+ // has to return the current Access principal — the console infers admin from
22+ // that list (`isCurrentUser` + role), and an empty list fail-closes every
23+ // workspace-admin action even when `ADMIN_EMAILS` granted `orgRole: "admin"` .
2424// ---------------------------------------------------------------------------
2525
2626const NOT_IN_APP = "Managed by Cloudflare Access, not in the app." ;
@@ -66,7 +66,28 @@ export const cloudflareAccountProvider = (
6666 listOrgApiKeys : ( ) => Effect . succeed ( { apiKeys : [ ] } ) ,
6767 createOrgApiKey : ( ) => forbiddenWrite ,
6868 revokeOrgApiKey : ( ) => forbiddenWrite ,
69- listMembers : ( ) => Effect . succeed ( { members : [ ] } ) ,
69+ listMembers : ( headers ) =>
70+ principalFrom ( headers ) . pipe (
71+ Effect . flatMap ( ( principal ) =>
72+ principal
73+ ? Effect . succeed ( {
74+ members : [
75+ {
76+ id : principal . accountId ,
77+ userId : principal . accountId ,
78+ email : principal . email . length > 0 ? principal . email : null ,
79+ name : principal . name ,
80+ avatarUrl : principal . avatarUrl ,
81+ role : principal . orgRole === "admin" ? "admin" : "member" ,
82+ status : "active" ,
83+ lastActiveAt : null ,
84+ isCurrentUser : true ,
85+ } ,
86+ ] ,
87+ } )
88+ : Effect . fail ( new AccountUnauthorized ( ) ) ,
89+ ) ,
90+ ) ,
7091 listRoles : ( ) => Effect . succeed ( { roles : [ ] } ) ,
7192 inviteMember : ( ) => forbiddenWrite ,
7293 removeMember : ( ) => forbiddenWrite ,
0 commit comments