Repository navigation
fix(plans): allow Read-Only users to view plans (closes #999) - #1004
Conversation
The Plans page loads its "Scheduled (Planned) Purchases" list via the GET /api/purchases/planned endpoint (getPlannedPurchases), which gated on view:purchases. A Read-Only user holds view:plans, view:recommendations, and view:history but NOT view:purchases (see auth.DefaultReadOnlyPermissions), so the page failed with "permission denied: requires view on purchases" and rendered no plans. This endpoint serves plan-scheduled data, not purchase-execution data, so it should gate on view:plans (mirroring listPlans), not view:purchases. Per-plan account scoping is still enforced via isPlanAllowedCached, and the pause/resume/run/delete mutations keep their stronger update/execute/delete :purchases gates, so Read-Only users can VIEW planned purchases but still cannot MANAGE them. Regression tests: - TestHandler_getPlannedPurchases_ReadOnlyCanView: a Read-Only session (view:plans yes, view:purchases no) lists planned purchases successfully. Fails pre-fix (403 on the view:purchases gate), passes post-fix. - TestHandler_getPlannedPurchases_ReadOnlyCannotManage: the same session is denied pausing (update:purchases), proving the relaxed view gate does not widen management access.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe PR fixes a permission gate in the ChangesAccess Control Fix for Planned Purchases
Possibly related PRs
Poem
🎯 2 (Simple) | ⏱️ ~12 minutes 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Problem
A Read-Only user opening the Plans page sees
Failed to load planned purchases: permission denied: requires view on purchasesand no plans. Per role design, Read-Only users SHOULD be able to view existing plans.Root cause
The Plans page loads its "Scheduled (Planned) Purchases" list via
GET /api/purchases/planned(getPlannedPurchases), which gated onview:purchases. The Read-Only role (auth.DefaultReadOnlyPermissions) holdsview:plans,view:recommendations, andview:historybut NOTview:purchases, so the gate returned 403 and the page rendered nothing.Fix
This endpoint serves plan-scheduled data, not purchase-execution data, so it now gates on
view:plans(mirroringlistPlans, which already usesview:plans).Scope is deliberately narrow:
isPlanAllowedCached.update/execute/delete:purchasesgates, so Read-Only users can VIEW planned purchases but still cannot MANAGE them.getPurchaseDetailsand other genuine purchase-execution reads keepview:purchases.Tests
TestHandler_getPlannedPurchases_ReadOnlyCanView: a Read-Only session (view:plansyes,view:purchasesno) lists planned purchases successfully. Verified to FAIL pre-fix (403 on theview:purchasesgate) and PASS post-fix.TestHandler_getPlannedPurchases_ReadOnlyCannotManage: the same session is denied pausing (update:purchases), proving the relaxed view gate does not widen management access.go build ./...succeeds;go test ./internal/api/...is green (the two pre-existinginternal/authMFA login-message failures are unrelated and also fail on the base branch).closes #999
Summary by CodeRabbit
Bug Fixes
view:planspermission can now view the scheduled purchases list on the Plans page.Tests