Skip to content

feat(api/auth): finer-grained per-role write permissions across plans/purchases/RI-exchange #660

Description

@cristim

PR #364 made the route Auth field mandatory and flipped 24 read endpoints to AuthUser so non-admin roles can use the app. All mutating endpoints (POST/PUT/PATCH/DELETE) were kept at AuthAdmin pending finer-grained per-role write permissions.

PR #364 listed this under "Out of scope (separate follow-ups)" without filing an issue. Capturing it now.

Scope (from PR #364's out-of-scope section):

  • Spread the existing handler-level requirePermission(action, resource) checks (currently on only a few endpoints) to plans / purchases / RI-exchange / etc., so role semantics become: readonly = read-only; user = read + write plans; admin = full.
  • Decide which admin-management endpoints (/api/users, /api/registrations, /api/accounts writes) should ever loosen to non-admin (default today: stay admin-only).
  • Audit requirePermission callers so no AuthUser route accidentally surfaces data outside the caller's allowed_accounts grant.

Out of scope when deferred: PR #364 was scoped to fixing the P0 (whole read surface was admin-gated) by making Auth explicit; the per-role write matrix is a larger design.

Deferred by: #364
Related: #289 (execute-{any,own} RBAC), #158 (cancel-any non-admin surface).

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions