Repository navigation
fix(frontend): surface Cancel button for non-admin operators with cancel-* (closes #158) - #835
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThis PR adds permission-gating to the History inline Cancel button using a granular role-based access control model. The ChangesCancel Button Permission-Gating Authorization
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai full review |
✅ Actions performedFull review triggered. |
…158) Replace the user.role === 'admin' check in canCancelPendingRow with the canAccess predicate pattern from PR #590: canAccess('admin', '*') || canAccess('cancel-any', 'purchases') || (canAccess('cancel-own', 'purchases') && row.created_by_user_id === user.id). Removes the deferred-work caveat block. Adds history-cancel-permissions.test.ts covering the full 6-case permission matrix.
|
Rebased on Conflict shape: Test-fixture follow-up from the rebase: post-#917 Full suite: 2228 passed / 0 failed / 1 skipped. tsc clean. Pre-commit clean. No new CR findings to address (the prior CR pass was rate-limited and the re-trigger from 2026-05-30 produced no inline comments). @coderabbitai full review |
|
One housekeeping note: the long-term memory entry from PR ⛔ Learnings removed🧠 Learnings used✅ Action performedFull review finished. |
Summary
user.role === 'admin'check incanCancelPendingRow(history.ts) with the samecanAccesspredicate pattern used bycanApproveRIExchangeRowin riexchange.ts (PR feat(ri-exchange): symmetric session-auth approve path (closes #300) #590):canAccess('admin', '*') || canAccess('cancel-any', 'purchases') || (canAccess('cancel-own', 'purchases') && row.created_by_user_id === user.id).history-cancel-permissions.test.tscovering admin / cancel-any / cancel-own-own-row / cancel-own-other-row / no-permission / anonymous matrix (6 new tests).Test plan
cd frontend && npx tsc --noEmit-- no type errorsnpx jest-- 2148 tests pass, 0 failureshistory-cancel-permissions.test.ts-- 6 new tests all greenhistory-cancel-button.test.ts-- 8 existing tests still green (no regression)cancel-any:purchasespermission sees Cancel button on all pending rowscancel-own:purchasessees Cancel only on their own rowsSummary by CodeRabbit
Tests
Refactor