Class lists: Photos authorization #2465
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Who is this PR for?
K8 teaching teams
What problem does this PR fix?
When creating class lists, there are parallel authorization rules that allow the teacher creating the list to view data for all students at a particular grade and school (if they are authorized to teach students in that grade). Student photos are still requested through
/students/:id/photo
however, which use standard authorization rules. This means that if a homeroom teacher started the class list process on behalf of the team, only their homeroom students will have pictures.What does this PR do?
Changes the UI code to use
/classlists/:workspace_id/students/:student_id/photo
for pictures, and use the class list authorization rules for guarding access. This allows the photos to be viewed more permissively only in this part of the product, and only when this feature is enabled (eg, at particular times of the year).Checklists
Which features or pages does this PR touch?
Does this PR use tests to help verify we can deploy these changes quickly and confidently?