Feat v0.9.9 surface access via roles

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-03 19:52:47 +00:00
parent b0e9dd7f80
commit 75dfdb3dcd
9 changed files with 359 additions and 6 deletions

View File

@@ -145,11 +145,13 @@ neq, gt, lt, gte, lte, in, contains), first-match-wins, returns target
string or None. Always available (pure computation, no permission).
8 new tests.
**v0.9.9 — Surface Access via Roles**
**v0.9.9 — Surface Access via Roles** *(completed)*
Wire team roles (v0.9.3) into surface access declarations:
`access: role:approver`. Kernel middleware checks role membership.
Completes the workflow→package access story.
`role:ROLENAME` surface access level. User must hold the role in any
team (any-team semantics, no URL context needed). `evaluateAccess`
promoted to Engine method for store access. `HasRoleInAnyTeam` store
method queries both primary and additional roles. Admin bypass, fail-
closed on nil store. 10 new tests.
---