Files
content-factory/tasks/004-auth-and-admin-editor-roles.md
T

121 lines
5.1 KiB
Markdown

# Task 004: Auth And Admin/Editor Roles
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
## Implementation Details
- Add a local-demo authentication mode suitable for Docker Compose:
- Header-based user selection for local demo, or
- Session login with seeded users.
- Enforce role checks at backend endpoint boundaries.
- Role capabilities:
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
- Add frontend role-aware navigation:
- Admin sees site configuration and script versioning screens.
- Editor sees pipeline execution and review screens.
- Ensure authorization failures return stable `403` responses.
## Public Interface
- Backend identifies current user and role for each request.
- Frontend can fetch `GET /api/me`.
- Protected endpoints consistently allow or deny Admin/Editor actions.
## Acceptance Criteria
- [x] TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in `Result`.
- [x] `GET /api/me` returns the active user and role.
- [x] Admin can create/update site config and script versions.
- [x] Editor cannot create/update site config or script versions.
- [x] Editor can create articles and perform review actions.
- [x] Unauthorized requests are rejected consistently.
- [x] Frontend hides Admin-only navigation for Editors.
## Verification
- Run backend authorization tests.
- Run frontend role rendering tests.
- Manually verify Admin and Editor demo sessions in Docker Compose.
## Result
- Status: Completed.
- TDD plan:
- First behavior slice: public FastAPI HTTP authorization denial for a demo
Editor attempting an Admin-only site configuration mutation.
- Public API contract selected for local demo auth:
`X-Demo-User-Email: editor@example.com`.
- Red test: `POST /api/sites` with an Editor-selected demo user must return
stable `403`.
- Green slices: `GET /api/me`, Admin allow/Editor deny for site config and
script version mutations, Editor article create and plan approval review
action, stable `401`/`403` responses, and role-aware frontend navigation.
- Red evidence:
- Command:
`docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py`
- Result: failed as expected because `POST /api/sites` and auth/role checks
are not implemented yet.
- Output:
```text
F
======================================================================
FAIL: test_editor_cannot_create_target_site_config (__main__.AuthAuthorizationPublicApiTest.test_editor_cannot_create_target_site_config)
----------------------------------------------------------------------
Traceback (most recent call last):
File "/app/apps/backend/tests/integration/test_auth_authorization_public_api.py", line 49, in test_editor_cannot_create_target_site_config
self.assertEqual(403, response.status_code, response.text)
AssertionError: 403 != 404 : {"detail":"Not Found"}
----------------------------------------------------------------------
Ran 1 test in 0.004s
FAILED (failures=1)
```
- Green evidence:
- Command:
`docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py`
- Output:
```text
........
----------------------------------------------------------------------
Ran 8 tests in 0.249s
OK
```
- Refactor notes:
- Added local demo auth via `X-Demo-User-Email` using seeded users.
- Kept role constants in domain, current-user/site-config orchestration in
application, repository persistence in infrastructure, and FastAPI
dependencies/guards in presentation.
- Added minimal plan approval review action endpoint for Task 004 role checks.
- Added FSD role navigation model/component and a deterministic Node test that
executes the TypeScript source.
- Regenerated `packages/shared/openapi.json` and `packages/shared/src/api-types.ts`.
- Verification output:
- `docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python -m unittest discover apps/backend/tests`
```text
..............s....
----------------------------------------------------------------------
Ran 19 tests in 0.364s
OK (skipped=1)
```
- `pnpm --filter @pipeline/frontend test:roles`
```text
role navigation hides Admin-only items for Editors
```
- `pnpm typecheck`
```text
@pipeline/shared typecheck: tsc --noEmit
@pipeline/frontend typecheck: tsc --noEmit
```
- `bash tests/smoke/public-health.sh`
```text
backend health ok
runner health ok
frontend health ok
backend dependencies ok
public health smoke ok
```