Repository navigation
Conversation
An Applies to picker on the Domains and Allowed tabs, and on the Add Blocked Domain and Add Allowed Domain dialogs, chooses between everyone's lists and one rule set's own. Adding, removing, importing, exporting and clearing all follow it. policyService takes the rule set, so the MCP allow_domain, block_domain and remove_domain_rule tools gain an optional rule_set too. Part of #240.
drudge
marked this pull request as draft
October 9, 2026 10:58
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Before: custom blocked and allowed domains always apply to every device. A rule set's own domains can only be typed into the rule set dialog on the Rule Sets tab.
After: the Blocked and Allowed tabs have an Applies to picker, offering Everyone or any rule set. Picking a rule set shows that rule set's own domains, with a line saying they apply only to its devices and win over everyone's. Add Domain, Import, Export, Clear All and each row's remove button all follow the picker. The Add Blocked Domain and Add Allowed Domain dialogs carry the same picker, defaulting to the one on the page, and a domain added to a rule set lands in that view. The picker only shows when there are rule sets, so nothing changes for anyone without one. The MCP
allow_domain,block_domainandremove_domain_ruletools gain an optionalrule_setargument.Part of #240 (PR 4c). The Bypass Clients move into a built-in rule set comes next as its own PR, because it needs the rule set dialog to take addresses and networks first.
How:
policyServicetakes a rule set on every change and works on adomainListspair (everyone's or the rule set's), so the lists stay exclusive inside each scope and the audit log recordsrule_set. An unknown rule set is refused with a 422.blockingViewreadsrule_setfrom the request, and a newGET /ui/blocking/domainsre-renders the page content when the picker changes. Export names the file after the rule set, such aswarehouse-blocked-domains.txt.Screenshots
Before shots are from
main. The rule set views and dialogs are new, so they have after shots only.Phone
Testing
go tool mage verifypasses.TestDomainTabsApplyToARuleSetcovers the picker, scoped add/remove/export, and an unknown rule set; the policy service and MCP tests cover the new argument.