Task 001: dockerized monorepo foundation

This commit is contained in:
2026-05-21 16:57:58 +03:00
commit d42f0c4392
83 changed files with 4236 additions and 0 deletions
+48
View File
@@ -0,0 +1,48 @@
# Task 004: Auth And Admin/Editor Roles
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
## Implementation Details
- Add a local-demo authentication mode suitable for Docker Compose:
- Header-based user selection for local demo, or
- Session login with seeded users.
- Enforce role checks at backend endpoint boundaries.
- Role capabilities:
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
- Add frontend role-aware navigation:
- Admin sees site configuration and script versioning screens.
- Editor sees pipeline execution and review screens.
- Ensure authorization failures return stable `403` responses.
## Public Interface
- Backend identifies current user and role for each request.
- Frontend can fetch `GET /api/me`.
- Protected endpoints consistently allow or deny Admin/Editor actions.
## Acceptance Criteria
- [ ] TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in `Result`.
- [ ] `GET /api/me` returns the active user and role.
- [ ] Admin can create/update site config and script versions.
- [ ] Editor cannot create/update site config or script versions.
- [ ] Editor can create articles and perform review actions.
- [ ] Unauthorized requests are rejected consistently.
- [ ] Frontend hides Admin-only navigation for Editors.
## Verification
- Run backend authorization tests.
- Run frontend role rendering tests.
- Manually verify Admin and Editor demo sessions in Docker Compose.
## Result
- Status: Pending execution.
- TDD plan: To be filled during execution.
- Red evidence: To be filled during execution.
- Green evidence: To be filled during execution.
- Refactor notes: To be filled during execution.
- Verification output: To be filled during execution.