Skip to content

bug(rbac): action buttons (write/delete/approve) not correctly gated by per-resource permissions for all groups (regression after #660/PR #891) #1418

Description

@cristim

Repro

  1. Log in with different group permission sets (e.g., Read-Only, Plan Authors, Standard User, Viewer).
  2. Navigate to Opportunities, Plans, and Purchases.
  3. Observe action buttons (Purchase, Plan, Approve, Cancel, Retry, Edit, Delete).

Expected

Action buttons are visible only to users whose role has the corresponding per-resource write permission. For example:

  • Read-Only users see no action buttons anywhere.
  • Plan Authors see Plan and Create Plan buttons, but not Purchase buttons.
  • Viewers see no action buttons.

Actual

Some action buttons are visible for roles that should not see them. The per-resource gating introduced by #660/PR #891 is not consistently enforced across all role/button combinations.

Context

Issue #660 ('feat(api/auth): finer-grained per-role write permissions') was closed as fixed by PR #891. QA marked the verification row as Fail after the PR merged. Re-test needed across all role/button combinations to identify remaining gaps.

Note: Specific confirmed cases tracked separately:

Sheet reference

Bugs and improvement suggestions tab, row 522.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions