Members and Roles as two sidebar entries - #301
Conversation
Each is gated on its own permission, so a session holding only one of them no longer lands on a page whose other half is a dead tab. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: simplify9/coderabbit/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🔇 Additional comments (5)
📝 SummarySummary
Risk: Security-sensitive areas: Client-side permission enforcement and route visibility changed. Members and Roles no longer appear or become accessible through a page containing an unauthorized tab. No backend authorization changes are included. Test coverage: Verified with 12 tests in Operational concerns: No migration or deployment procedure is required. Existing bookmarks remain supported through WalkthroughThe team area now uses separate Members and Roles pages. Routes, permission guards, legacy ChangesTeam area restructuring
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested labels: Suggested reviewers: Merge Risk: ⚪ Minimal · up to Members and Roles routes are independently permission-gated, and legacy team links continue to redirect to an accessible page for users with either view permission. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Closes HAM-57.
Members and Roles were tabs inside one "Team" page gated on
users.view OR roles.view. They are now two sidebar entries under Administration, each gated on its own permission — a session holding only one no longer lands on a page whose other half is a dead tab. The role editor's access preview lists them separately for the same reason.URLs are unchanged (
/team/members,/team/roles) since the audit trail deep-links to/team/members/:id;/teamstays as a redirect for existing bookmarks.Verified in the browser, and the 12 tests in
team-roles.spec.ts+permissions-enforcement.spec.tspass.🤖 Generated with Claude Code