PR #364 made the route Auth field mandatory and flipped 24 read endpoints to AuthUser so non-admin roles can use the app. All mutating endpoints (POST/PUT/PATCH/DELETE) were kept at AuthAdmin pending finer-grained per-role write permissions.
PR #364 listed this under "Out of scope (separate follow-ups)" without filing an issue. Capturing it now.
Scope (from PR #364's out-of-scope section):
- Spread the existing handler-level
requirePermission(action, resource) checks (currently on only a few endpoints) to plans / purchases / RI-exchange / etc., so role semantics become: readonly = read-only; user = read + write plans; admin = full.
- Decide which admin-management endpoints (
/api/users, /api/registrations, /api/accounts writes) should ever loosen to non-admin (default today: stay admin-only).
- Audit
requirePermission callers so no AuthUser route accidentally surfaces data outside the caller's allowed_accounts grant.
Out of scope when deferred: PR #364 was scoped to fixing the P0 (whole read surface was admin-gated) by making Auth explicit; the per-role write matrix is a larger design.
Deferred by: #364
Related: #289 (execute-{any,own} RBAC), #158 (cancel-any non-admin surface).
PR #364 made the route
Authfield mandatory and flipped 24 read endpoints toAuthUserso non-admin roles can use the app. All mutating endpoints (POST/PUT/PATCH/DELETE) were kept atAuthAdminpending finer-grained per-role write permissions.PR #364 listed this under "Out of scope (separate follow-ups)" without filing an issue. Capturing it now.
Scope (from PR #364's out-of-scope section):
requirePermission(action, resource)checks (currently on only a few endpoints) to plans / purchases / RI-exchange / etc., so role semantics become: readonly = read-only; user = read + write plans; admin = full./api/users,/api/registrations,/api/accountswrites) should ever loosen to non-admin (default today: stay admin-only).requirePermissioncallers so noAuthUserroute accidentally surfaces data outside the caller'sallowed_accountsgrant.Out of scope when deferred: PR #364 was scoped to fixing the P0 (whole read surface was admin-gated) by making Auth explicit; the per-role write matrix is a larger design.
Deferred by: #364
Related: #289 (execute-{any,own} RBAC), #158 (cancel-any non-admin surface).