Cover image for project: Nexus Groups IN PROGRESS

Technical summary

Native NEXUS plugin for managing user groups and enforcing ACLs across core plugins. Task, profile, AI and per-plugin permissions are combined across the operator groups, while administrators and internal authentication retain access; the interface manages members, protected groups and webhook events.

Executed scope

  • groups_init_db() — DDL and seed from the plugin itself (no install.sql): creates nx_groups and nx_group_members, auto-migrates the permissions column, seeds admin/members with default permissions and auto-binds existing users by role.
  • 4 API actions via PluginManager::registerApiAction — groups_list (groups + core_plugins for the UI, compatible with legacy array payload), groups_save (creates with uniqid('grp_') or edits; protects system group names), groups_delete (blocks admin/members), groups_members_save (added/removed diff + upsert).
  • Per-core-plugin ACL: groups_core_plugins() lists is_core/protected/NEXUS or Administração category plugins; groups_normalize_permissions() guarantees plugin_access[slug] = { functions, tasks } for all (default: functions ← access_plugins/access_admin; tasks ← view_tasks/access_admin).
  • groups_user_plugin_flag($username, $slug, flag) — OR across groups, null when no group defines a policy, bypass on api_master_auth/api_node_auth.
  • Core integration: PluginManager::userHasAccess() (core/plugin-loader.php:315) → groups_user_plugin_flag(...,'functions') (blocks tab/actions); task hooks (lines 228-251) → 'tasks' flag (task_read/comment_* filters); system Admin always allowed.
  • Users integration: users.php enriches the user listing with their groups (JOIN nx_group_members/nx_groups) and binds a group in user_save.
  • Webhooks: webhook.php declares 5 events — group.created, group.updated, group.deleted, group.member_added, group.member_removed — dispatched via webhook_dispatch() in the backend (member diff in group_members_save).
  • Alpine.js UI: tab.php (169 lines) — ultra compact table with search, client-side pagination (5/10/20/50), role-based member badges, "Sistema" badge for default groups, "Novo Grupo" button and edit/delete actions (delete hidden for admin/members); modals/group.php (22 KB) — modal with operator picker (search), permission flags and the plugin_access[p.slug] grid per core plugin (with x-if avoiding Alpine errors with the modal closed).
  • Registrations: registerTab("groups", "Grupos", "users", tab.php, "NEXUS"), registerDoc("groups", "Gerenciamento de Grupos", "users", doc.md), registerModal("group", modals/group.php).

Stack and tooling

  • PHP 8 (no framework)
  • MySQL 8 (nx_groups, nx_group_members)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager::registerTab/registerDoc/registerModal/registerApiAction)
  • NEXUS webhooks (webhook_dispatch)

Operational tags

  • Groups
  • Permissions
  • ACL
  • Operators
  • RBAC
  • Plugin NEXUS
  • Webhooks

Operational outcome

  • Full NEXUS RBAC: operator groups with granular permissions and per-core-plugin ACL (functions/tasks) evaluated directly by PluginManager::userHasAccess — without the plugin, every user had access to all tabs/actions.
  • System Admin always passes and admin/members groups are protected (immutable name, deletion blocked), guaranteeing there is never a panel without a master group.
  • OR union across groups: an operator inherits the highest permission among all groups they belong to; null (no policy) keeps default behavior without restricting.
  • Lifecycle webhooks (create/edit/delete group, add/remove operator) enable external automation and auditing of access changes.
  • Zero migration: DDL + seed run on plugin load, with auto-migration of the permissions column on legacy installs.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Native NEXUS plugin (is_core) for user groups and access levels: per-core-plugin ACL (functions/tasks), granular permissions, operator assignment and webhook events — with OR between groups and system Admin always allowed.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.