Skip to content

Commit 91b74ee

Browse files
Update API documentation and refine role permission filtering
- Enhanced API documentation for the `GET /roles` endpoint to clarify the `permissionIds` query parameter, specifying that it now accepts a repeated Guid to match roles with any of the given permissions. - Refined the role permission filtering logic in `RoleService` to improve performance and accuracy by selecting role IDs based on the provided permission IDs, ensuring only relevant roles are returned in the query.
1 parent 48a4ba2 commit 91b74ee

2 files changed

Lines changed: 8 additions & 3 deletions

File tree

‎docs/API.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -289,7 +289,7 @@ Requires `X-Tenant-Id` header for SystemAdmin. Custom roles only — `SystemAdmi
289289

290290
| Method | Path | Permission | Notes |
291291
|--------|------|------------|-------|
292-
| GET | `/roles` | `Roles.List` | List custom roles. Query: `page`, `pageSize`, `search` (name), `permissionIds` (Guid list), `sortBy` (`name`), `sortOrder` (`asc`\|`desc`) |
292+
| GET | `/roles` | `Roles.List` | List custom roles. Query: `page`, `pageSize`, `search` (name), `permissionIds` (repeated Guid — matches roles having **any** of the given permissions), `sortBy` (`name`), `sortOrder` (`asc`\|`desc`) |
293293
| GET | `/roles/{name}` | `Roles.View` | Get role details by name |
294294
| GET | `/roles/current` | `Roles.View` | Caller's own role |
295295
| POST | `/roles` | `Roles.Create` | Create custom role with permissions |

‎src/Infrastructure/Roles/RoleService.cs‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -63,8 +63,13 @@ public async Task<PagedResponse<RoleResponse>> GetRolesAsync(
6363

6464
if (permissionIds is { Count: > 0 })
6565
{
66-
query = query.Where(r => _context.RolePermissions
67-
.Any(rp => rp.RoleId == r.Id && permissionIds.Contains(rp.PermissionId)));
66+
var selectedPermissionIds = permissionIds.ToList();
67+
var roleIdsWithPermission = _context.RolePermissions
68+
.Where(rp => selectedPermissionIds.Contains(rp.PermissionId))
69+
.Select(rp => rp.RoleId)
70+
.Distinct();
71+
72+
query = query.Where(r => roleIdsWithPermission.Contains(r.Id));
6873
}
6974

7075
var totalCount = await query.CountAsync();

0 commit comments

Comments
 (0)