-
Notifications
You must be signed in to change notification settings - Fork 4
feat(authz): [FC-0099] update state to return the libraries roles and permissions metadata #5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Thanks for the pull request, @dcoa! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. Where can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #5 +/- ##
==========================================
+ Coverage 89.82% 90.71% +0.89%
==========================================
Files 18 19 +1
Lines 167 183 +16
Branches 23 22 -1
==========================================
+ Hits 150 166 +16
Misses 17 17 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
holaontiveros
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, pretty consistent with the previous PR, I have to test it during the day but I need to setup my local env properly
|
@arbrandes could you please help me to review this PR? this unblock the rest of PRs |
| { key: 'library_team', label: 'Team', description: 'Permissions to manage user access and roles within the library.' }, | ||
| ]; | ||
|
|
||
| export const libraryPermissions: PermissionMetadata[] = [ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is not a blocker comment, but I think it will be helpful to align the name of the permission and the grouping with this: https://openedx.atlassian.net/wiki/spaces/OEPM/pages/4840095745/Library+Roles+and+Permissions#Table-of-Roles-and-Permissions
I know we had something different in the Hi-Fi design, but after discussing it with @gviedma-aulasneo, we agreed that it's best to maintain the grouping as mentioned in the URL.
Note: It only modifies the library and library _content grouping.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank @MaferMazu I updated it accordingly.
bra-i-am
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @dcoa! I've tested this PR with some other features, and it works as expected!
| const LIBRARY_TEAM_PERMISSIONS = ['act:view_library_team', 'act:manage_library_team']; | ||
| const LIBRARY_TEAM_PERMISSIONS = ['view_library_team', 'manage_library_team']; | ||
| // Note: This value can change in the future | ||
| const LIBRARY_AUTHZ_SCOPE = '*'; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Discussion related to this definition openedx/openedx-authz#84 (comment)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[Update] Final decision on this, send the libraryId
…pping of roles and permissions
|
@arbrandes just a friendly remainder on this. |
arbrandes
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry it took me a while. This looks great! Approved.
Libraries roles and permissions metadata
Description
This PR introduces the metadata for roles, permissions and library resources.
Roles
Each role includes:
library_admin,library_user)Resources
A library resource refers to the specific entity on which an action can be performed (e.g., Teams, Collections). The metadata includes:
Permissions
A
permissionis the action that a role can execute over a resource, includes:Changes description
usePermissionsByRole. The backend will retrieve the list of roles, the allowed permissions for each role, and the number of users associated with each role.LIBRARY_AUTHZ_SCOPE = 'lib:*'to retrieve all the permissions available in libraries.scopehere the conversation about it docs: add ADR for defining API for querying permissions from MFEs for current user FC-0099 openedx-authz#60Additional information
TeamMemberstype because the backend will send the full name if available related changeImportant
Although the API is still being defined and the initial version introduced here may undergo changes, this PR is important to continue the development of the rest of the UI.