( org: Organization, membership: ActiveMembership, options: AuthorizeOrganizationOptions, )
| 187 | // workspace write permission without a second read. WorkOS issues `admin` / |
| 188 | // `member`; anything unrecognized stays a plain member. |
| 189 | const authorized = ( |
| 190 | org: Organization, |
| 191 | membership: ActiveMembership, |
| 192 | options: AuthorizeOrganizationOptions, |
| 193 | ) => { |
| 194 | if (org.deletedAt !== null && options.deleted !== "allow") return null; |
| 195 | const memberRole: "admin" | "member" = membership.role === "admin" ? "admin" : "member"; |
| 196 | return { ...org, memberRole }; |
| 197 | }; |
| 198 | |
| 199 | // The organization row for a caller, minted from WorkOS when the mirror |
| 200 | // does not hold it — only for a caller WorkOS confirms as its member (see |
no outgoing calls
no test coverage detected