* refactor: implement PBAC for team member listing
- Replace membership-based team filtering with getTeamIdsWithPermission
- Use team.listMembers permission for access control
- Maintain fallback to original logic when PBAC fails
- Add comprehensive PBAC refactoring guide for future use
Fixes team fetching logic to use Permission-Based Access Control
while preserving existing functionality and privacy checks.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: move PBAC refactoring guide to packages/features/pbac/
Move the PBAC refactoring guide to the appropriate location within
the PBAC feature package for better organization and discoverability.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: remove unnecessary try-catch wrapper
The getTeamIdsWithPermission method already handles all errors internally
and returns an empty array instead of throwing exceptions, making the
try-catch wrapper redundant. Simplified to use direct fallback logic
based on empty array return.
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* refactor: simplify PBAC implementation
- Remove flawed fallback logic that assumed empty array meant PBAC failure
- Use direct string 'team.listMembers' instead of PermissionMapper
- Remove unused imports (PermissionMapper, Resource, CustomAction)
- Empty array from getTeamIdsWithPermission is legitimate (no permissions)
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
* docs: simplify PBAC refactoring guide
- Reduce from 260 to 87 lines by removing bloated content
- Focus on core pattern: direct permission strings, no fallback logic
- Align with actual PR implementation
- Remove verbose theoretical sections and complex patterns
Co-Authored-By: eunjae@cal.com <hey@eunjae.dev>
---------
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>