Skip to content

Conversation

@dcoa
Copy link
Contributor

@dcoa dcoa commented Oct 1, 2025

Libraries roles and permissions metadata

Description

This PR introduces the metadata for roles, permissions and library resources.

Roles
Each role includes:

  • A key 'role' defined in the AuthZ Policy (e.g., library_admin, library_user)
  • A description explaining the role's responsibilities and limitations
  • A key 'name' , which is the human-readable name displayed to the end user

Resources
A library resource refers to the specific entity on which an action can be performed (e.g., Teams, Collections). The metadata includes:

  • A key defined in the AuthZ Policy (e.g., library_team, library_collection)
  • A description outlining the types of actions allowed on the resource
  • A label for UI display

Permissions
A permission is the action that a role can execute over a resource, includes:

  • A key defined in the AuthZ Policy (e.g., manage_library_team, edit_library_collection)
  • The resource to which the action applies
  • A description of the action's capabilities and limitations

Changes description

  • Added the metadata objects for roles, resources and permissions.
  • Created the hook usePermissionsByRole. The backend will retrieve the list of roles, the allowed permissions for each role, and the number of users associated with each role.
# backend response 
[
   {
      "role":"library_admin",
       "permissions":[
         "edit_library",
         ...
      ],
      "user_count":5,
   },
  ...
]

Additional information

Important

Although the API is still being defined and the initial version introduced here may undergo changes, this PR is important to continue the development of the rest of the UI.

@openedx-webhooks openedx-webhooks added open-source-contribution PR author is not from Axim or 2U core contributor PR author is a Core Contributor (who may or may not have write access to this repo). labels Oct 1, 2025
@openedx-webhooks
Copy link

openedx-webhooks commented Oct 1, 2025

Thanks for the pull request, @dcoa!

This repository is currently maintained by @openedx/committers-frontend.

Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review.

🔘 Get product approval

If you haven't already, check this list to see if your contribution needs to go through the product review process.

  • If it does, you'll need to submit a product proposal for your contribution, and have it reviewed by the Product Working Group.
    • This process (including the steps you'll need to take) is documented here.
  • If it doesn't, simply proceed with the next step.
🔘 Provide context

To help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:

  • Dependencies

    This PR must be merged before / after / at the same time as ...

  • Blockers

    This PR is waiting for OEP-1234 to be accepted.

  • Timeline information

    This PR must be merged by XX date because ...

  • Partner information

    This is for a course on edx.org.

  • Supporting documentation
  • Relevant Open edX discussion forum threads
🔘 Get a green build

If one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green.


Where can I find more information?

If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources:

When can I expect my changes to be merged?

Our goal is to get community contributions seen and reviewed as efficiently as possible.

However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:

  • The size and impact of the changes that it introduces
  • The need for product review
  • Maintenance status of the parent repository

💡 As a result it may take up to several weeks or months to complete a review and merge your PR.

@codecov
Copy link

codecov bot commented Oct 1, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.71%. Comparing base (6d8f6fa) to head (7a834bf).
⚠️ Report is 7 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master       #5      +/-   ##
==========================================
+ Coverage   89.82%   90.71%   +0.89%     
==========================================
  Files          18       19       +1     
  Lines         167      183      +16     
  Branches       23       22       -1     
==========================================
+ Hits          150      166      +16     
  Misses         17       17              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dcoa dcoa marked this pull request as ready for review October 2, 2025 01:58
@dcoa dcoa changed the title feat: update state to return the roles and permissions metadata feat(FC-99): update state to return the roles and permissions metadata Oct 2, 2025
@dcoa dcoa changed the title feat(FC-99): update state to return the roles and permissions metadata feat: [FC-0099] update state to return the roles and permissions metadata Oct 2, 2025
@dcoa dcoa changed the title feat: [FC-0099] update state to return the roles and permissions metadata feat(authz): [FC-0099] update state to return the libraries roles and permissions metadata Oct 2, 2025
Copy link

@holaontiveros holaontiveros left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, pretty consistent with the previous PR, I have to test it during the day but I need to setup my local env properly

@mphilbrick211 mphilbrick211 added the FC Relates to an Axim Funded Contribution project label Oct 2, 2025
@mphilbrick211 mphilbrick211 moved this from Needs Triage to Ready for Review in Contributions Oct 2, 2025
@dcoa
Copy link
Contributor Author

dcoa commented Oct 6, 2025

@arbrandes could you please help me to review this PR? this unblock the rest of PRs

{ key: 'library_team', label: 'Team', description: 'Permissions to manage user access and roles within the library.' },
];

export const libraryPermissions: PermissionMetadata[] = [
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is not a blocker comment, but I think it will be helpful to align the name of the permission and the grouping with this: https://openedx.atlassian.net/wiki/spaces/OEPM/pages/4840095745/Library+Roles+and+Permissions#Table-of-Roles-and-Permissions
I know we had something different in the Hi-Fi design, but after discussing it with @gviedma-aulasneo, we agreed that it's best to maintain the grouping as mentioned in the URL.
Note: It only modifies the library and library _content grouping.

Copy link
Contributor Author

@dcoa dcoa Oct 7, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank @MaferMazu I updated it accordingly.

Copy link
Contributor

@bra-i-am bra-i-am left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @dcoa! I've tested this PR with some other features, and it works as expected!

const LIBRARY_TEAM_PERMISSIONS = ['act:view_library_team', 'act:manage_library_team'];
const LIBRARY_TEAM_PERMISSIONS = ['view_library_team', 'manage_library_team'];
// Note: This value can change in the future
const LIBRARY_AUTHZ_SCOPE = '*';
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussion related to this definition openedx/openedx-authz#84 (comment)

Copy link
Contributor Author

@dcoa dcoa Oct 13, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Update] Final decision on this, send the libraryId

@dcoa
Copy link
Contributor Author

dcoa commented Oct 15, 2025

@arbrandes just a friendly remainder on this.

Copy link

@arbrandes arbrandes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry it took me a while. This looks great! Approved.

@arbrandes arbrandes merged commit c5cab49 into openedx:master Oct 16, 2025
6 checks passed
@github-project-automation github-project-automation bot moved this from Ready for Review to Done in Contributions Oct 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core contributor PR author is a Core Contributor (who may or may not have write access to this repo). FC Relates to an Axim Funded Contribution project open-source-contribution PR author is not from Axim or 2U

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

7 participants