# Task 004: Auth And Admin/Editor Roles Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor. ## Implementation Details - Add a local-demo authentication mode suitable for Docker Compose: - Header-based user selection for local demo, or - Session login with seeded users. - Enforce role checks at backend endpoint boundaries. - Role capabilities: - Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles. - Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits. - Add frontend role-aware navigation: - Admin sees site configuration and script versioning screens. - Editor sees pipeline execution and review screens. - Ensure authorization failures return stable `403` responses. ## Public Interface - Backend identifies current user and role for each request. - Frontend can fetch `GET /api/me`. - Protected endpoints consistently allow or deny Admin/Editor actions. ## Acceptance Criteria - [x] TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in `Result`. - [x] `GET /api/me` returns the active user and role. - [x] Admin can create/update site config and script versions. - [x] Editor cannot create/update site config or script versions. - [x] Editor can create articles and perform review actions. - [x] Unauthorized requests are rejected consistently. - [x] Frontend hides Admin-only navigation for Editors. ## Verification - Run backend authorization tests. - Run frontend role rendering tests. - Manually verify Admin and Editor demo sessions in Docker Compose. ## Result - Status: Completed. - TDD plan: - First behavior slice: public FastAPI HTTP authorization denial for a demo Editor attempting an Admin-only site configuration mutation. - Public API contract selected for local demo auth: `X-Demo-User-Email: editor@example.com`. - Red test: `POST /api/sites` with an Editor-selected demo user must return stable `403`. - Green slices: `GET /api/me`, Admin allow/Editor deny for site config and script version mutations, Editor article create and plan approval review action, stable `401`/`403` responses, and role-aware frontend navigation. - Red evidence: - Command: `docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py` - Result: failed as expected because `POST /api/sites` and auth/role checks are not implemented yet. - Output: ```text F ====================================================================== FAIL: test_editor_cannot_create_target_site_config (__main__.AuthAuthorizationPublicApiTest.test_editor_cannot_create_target_site_config) ---------------------------------------------------------------------- Traceback (most recent call last): File "/app/apps/backend/tests/integration/test_auth_authorization_public_api.py", line 49, in test_editor_cannot_create_target_site_config self.assertEqual(403, response.status_code, response.text) AssertionError: 403 != 404 : {"detail":"Not Found"} ---------------------------------------------------------------------- Ran 1 test in 0.004s FAILED (failures=1) ``` - Green evidence: - Command: `docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py` - Output: ```text ........ ---------------------------------------------------------------------- Ran 8 tests in 0.249s OK ``` - Refactor notes: - Added local demo auth via `X-Demo-User-Email` using seeded users. - Kept role constants in domain, current-user/site-config orchestration in application, repository persistence in infrastructure, and FastAPI dependencies/guards in presentation. - Added minimal plan approval review action endpoint for Task 004 role checks. - Added FSD role navigation model/component and a deterministic Node test that executes the TypeScript source. - Regenerated `packages/shared/openapi.json` and `packages/shared/src/api-types.ts`. - Verification output: - `docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python -m unittest discover apps/backend/tests` ```text ..............s.... ---------------------------------------------------------------------- Ran 19 tests in 0.364s OK (skipped=1) ``` - `pnpm --filter @pipeline/frontend test:roles` ```text role navigation hides Admin-only items for Editors ``` - `pnpm typecheck` ```text @pipeline/shared typecheck: tsc --noEmit @pipeline/frontend typecheck: tsc --noEmit ``` - `bash tests/smoke/public-health.sh` ```text backend health ok runner health ok frontend health ok backend dependencies ok public health smoke ok ```