Feat v0.9.9 surface access roles (#83)
All checks were successful
CI/CD / detect-changes (push) Successful in 3s
CI/CD / test-runners (push) Has been skipped
CI/CD / e2e-smoke (push) Has been skipped
CI/CD / test-frontend (push) Successful in 5s
CI/CD / test-go-pg (push) Successful in 2m49s
CI/CD / test-sqlite (push) Successful in 2m59s
CI/CD / build-and-deploy (push) Successful in 1m28s
All checks were successful
CI/CD / detect-changes (push) Successful in 3s
CI/CD / test-runners (push) Has been skipped
CI/CD / e2e-smoke (push) Has been skipped
CI/CD / test-frontend (push) Successful in 5s
CI/CD / test-go-pg (push) Successful in 2m49s
CI/CD / test-sqlite (push) Successful in 2m59s
CI/CD / build-and-deploy (push) Successful in 1m28s
Co-authored-by: Jeffrey Smith <jasafpro@gmail.com> Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #83.
This commit is contained in:
10
ROADMAP.md
10
ROADMAP.md
@@ -145,11 +145,13 @@ neq, gt, lt, gte, lte, in, contains), first-match-wins, returns target
|
||||
string or None. Always available (pure computation, no permission).
|
||||
8 new tests.
|
||||
|
||||
**v0.9.9 — Surface Access via Roles**
|
||||
**v0.9.9 — Surface Access via Roles** *(completed)*
|
||||
|
||||
Wire team roles (v0.9.3) into surface access declarations:
|
||||
`access: role:approver`. Kernel middleware checks role membership.
|
||||
Completes the workflow→package access story.
|
||||
`role:ROLENAME` surface access level. User must hold the role in any
|
||||
team (any-team semantics, no URL context needed). `evaluateAccess`
|
||||
promoted to Engine method for store access. `HasRoleInAnyTeam` store
|
||||
method queries both primary and additional roles. Admin bypass, fail-
|
||||
closed on nil store. 10 new tests.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user