Skip to main content

merge_user_vault_write

Function merge_user_vault_write 

Source
pub fn merge_user_vault_write(
    full_vault: Value,
    user_data: Value,
    read: Option<&Expr>,
    write: Option<&Expr>,
) -> Result<Value, String>
Expand description

Merges a user’s submitted vault data into the full vault, respecting write permissions.

  • Entries the user submitted within their write scope → applied (add / update).
  • Entries in the user’s write scope that are absent from the submission → deleted.
  • Entries outside the user’s write scope → unchanged from full_vault.
  • projects and user_categories are merged the same way, against what the read expression would have served, with container writability defined as “every entry inside it is writable”.

Returns Err if the user’s submission contains an entry outside their write scope, or changes a project or category they may not change.

projects and user_categories used to be dropped silently. The merge rebuilt api_keys only and took both collections from full_vault, and the server answered 204 No Content. A sub-user creating a project, renaming a category, editing a WireGuard peer or adding a chunk got a success toast and a UI that showed the change — because the frontend had already applied it to its own copy — while the server persisted nothing. It surfaced on the next reload, attributable to nothing.