121 lines
5.1 KiB
Markdown
121 lines
5.1 KiB
Markdown
# Task 004: Auth And Admin/Editor Roles
|
|
|
|
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
|
|
|
|
## Implementation Details
|
|
|
|
- Add a local-demo authentication mode suitable for Docker Compose:
|
|
- Header-based user selection for local demo, or
|
|
- Session login with seeded users.
|
|
- Enforce role checks at backend endpoint boundaries.
|
|
- Role capabilities:
|
|
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
|
|
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
|
|
- Add frontend role-aware navigation:
|
|
- Admin sees site configuration and script versioning screens.
|
|
- Editor sees pipeline execution and review screens.
|
|
- Ensure authorization failures return stable `403` responses.
|
|
|
|
## Public Interface
|
|
|
|
- Backend identifies current user and role for each request.
|
|
- Frontend can fetch `GET /api/me`.
|
|
- Protected endpoints consistently allow or deny Admin/Editor actions.
|
|
|
|
## Acceptance Criteria
|
|
|
|
- [x] TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in `Result`.
|
|
- [x] `GET /api/me` returns the active user and role.
|
|
- [x] Admin can create/update site config and script versions.
|
|
- [x] Editor cannot create/update site config or script versions.
|
|
- [x] Editor can create articles and perform review actions.
|
|
- [x] Unauthorized requests are rejected consistently.
|
|
- [x] Frontend hides Admin-only navigation for Editors.
|
|
|
|
## Verification
|
|
|
|
- Run backend authorization tests.
|
|
- Run frontend role rendering tests.
|
|
- Manually verify Admin and Editor demo sessions in Docker Compose.
|
|
|
|
## Result
|
|
|
|
- Status: Completed.
|
|
- TDD plan:
|
|
- First behavior slice: public FastAPI HTTP authorization denial for a demo
|
|
Editor attempting an Admin-only site configuration mutation.
|
|
- Public API contract selected for local demo auth:
|
|
`X-Demo-User-Email: editor@example.com`.
|
|
- Red test: `POST /api/sites` with an Editor-selected demo user must return
|
|
stable `403`.
|
|
- Green slices: `GET /api/me`, Admin allow/Editor deny for site config and
|
|
script version mutations, Editor article create and plan approval review
|
|
action, stable `401`/`403` responses, and role-aware frontend navigation.
|
|
- Red evidence:
|
|
- Command:
|
|
`docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py`
|
|
- Result: failed as expected because `POST /api/sites` and auth/role checks
|
|
are not implemented yet.
|
|
- Output:
|
|
```text
|
|
F
|
|
======================================================================
|
|
FAIL: test_editor_cannot_create_target_site_config (__main__.AuthAuthorizationPublicApiTest.test_editor_cannot_create_target_site_config)
|
|
----------------------------------------------------------------------
|
|
Traceback (most recent call last):
|
|
File "/app/apps/backend/tests/integration/test_auth_authorization_public_api.py", line 49, in test_editor_cannot_create_target_site_config
|
|
self.assertEqual(403, response.status_code, response.text)
|
|
AssertionError: 403 != 404 : {"detail":"Not Found"}
|
|
|
|
----------------------------------------------------------------------
|
|
Ran 1 test in 0.004s
|
|
|
|
FAILED (failures=1)
|
|
```
|
|
- Green evidence:
|
|
- Command:
|
|
`docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py`
|
|
- Output:
|
|
```text
|
|
........
|
|
----------------------------------------------------------------------
|
|
Ran 8 tests in 0.249s
|
|
|
|
OK
|
|
```
|
|
- Refactor notes:
|
|
- Added local demo auth via `X-Demo-User-Email` using seeded users.
|
|
- Kept role constants in domain, current-user/site-config orchestration in
|
|
application, repository persistence in infrastructure, and FastAPI
|
|
dependencies/guards in presentation.
|
|
- Added minimal plan approval review action endpoint for Task 004 role checks.
|
|
- Added FSD role navigation model/component and a deterministic Node test that
|
|
executes the TypeScript source.
|
|
- Regenerated `packages/shared/openapi.json` and `packages/shared/src/api-types.ts`.
|
|
- Verification output:
|
|
- `docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python -m unittest discover apps/backend/tests`
|
|
```text
|
|
..............s....
|
|
----------------------------------------------------------------------
|
|
Ran 19 tests in 0.364s
|
|
|
|
OK (skipped=1)
|
|
```
|
|
- `pnpm --filter @pipeline/frontend test:roles`
|
|
```text
|
|
role navigation hides Admin-only items for Editors
|
|
```
|
|
- `pnpm typecheck`
|
|
```text
|
|
@pipeline/shared typecheck: tsc --noEmit
|
|
@pipeline/frontend typecheck: tsc --noEmit
|
|
```
|
|
- `bash tests/smoke/public-health.sh`
|
|
```text
|
|
backend health ok
|
|
runner health ok
|
|
frontend health ok
|
|
backend dependencies ok
|
|
public health smoke ok
|
|
```
|