Repository navigation
feat(ui): gate Purchases + Inventory pages on view:purchases (closes #1000) - #1003
Conversation
…1000) A read-only user (no view:purchases) was shown raw "permission denied" backend error banners on the Purchases page and the Inventory & Coverage pages (Active Commitments, Coverage, RI Exchange). Fix: reuse the existing admin-only CSS/JS pattern with a new requires-purchases class. updateUserUI() in auth.ts now toggles the Purchases and Inventory nav entries visible only when canAccess('view', 'purchases') is true. switchTab() in navigation.ts guards both cases: when the user lacks the permission, renderNoAccess() places a friendly "You do not have access" empty-state paragraph and returns early so no API call is fired. Direct URL navigation (including legacy /history and /ri-exchange aliases) hits the same guard. No regression for users who have view:purchases (admins, standard users).
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Linter diff in the way? Review this PR in Change Stack to focus on meaningful changes and expand context only when needed. Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (6)
📝 WalkthroughWalkthroughThis PR implements permission-gated navigation for purchases-related pages and tabs. Users lacking ChangesPurchases Permission Gating
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested labels
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Summary
requires-purchasesCSS class (mirrorsadmin-onlypattern) to the Purchases and Inventory & Coverage nav entries so they are hidden by default and shown only whencanAccess('view', 'purchases')is true.updateUserUI()inauth.tstoggles.requires-purchaseselements visible after login, exactly as it does for.admin-only.switchTab()innavigation.tsguards both thepurchasesandinventorycases: when the user lacks the permission,renderNoAccess()places a friendly empty-state paragraph and returns early so no API call is fired. Covers direct URL navigation (including legacy/historyand/ri-exchangealiases).Permission string used:
view:purchases(confirmed from backend handler comments ininternal/api/handler_inventory.goandhandler_history.go).closes #1000
Test plan
auth.test.ts: 3 new tests coveringrequires-purchasesvisibility for user-with-permission, read-only-user-without-permission, and adminnavigation.test.ts: 6 new tests inview:purchases gatedescribe block - verify no API calls fired and no-access placeholder rendered for bothpurchasesandinventorytabs; verify normal operation when permission is presenttsc --noEmitcleannpm run buildsucceedsSummary by CodeRabbit
New Features
Tests