5.1 KiB
5.1 KiB
Task 004: Auth And Admin/Editor Roles
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
Implementation Details
- Add a local-demo authentication mode suitable for Docker Compose:
- Header-based user selection for local demo, or
- Session login with seeded users.
- Enforce role checks at backend endpoint boundaries.
- Role capabilities:
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
- Add frontend role-aware navigation:
- Admin sees site configuration and script versioning screens.
- Editor sees pipeline execution and review screens.
- Ensure authorization failures return stable
403responses.
Public Interface
- Backend identifies current user and role for each request.
- Frontend can fetch
GET /api/me. - Protected endpoints consistently allow or deny Admin/Editor actions.
Acceptance Criteria
- TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in
Result. GET /api/mereturns the active user and role.- Admin can create/update site config and script versions.
- Editor cannot create/update site config or script versions.
- Editor can create articles and perform review actions.
- Unauthorized requests are rejected consistently.
- Frontend hides Admin-only navigation for Editors.
Verification
- Run backend authorization tests.
- Run frontend role rendering tests.
- Manually verify Admin and Editor demo sessions in Docker Compose.
Result
- Status: Completed.
- TDD plan:
- First behavior slice: public FastAPI HTTP authorization denial for a demo Editor attempting an Admin-only site configuration mutation.
- Public API contract selected for local demo auth:
X-Demo-User-Email: editor@example.com. - Red test:
POST /api/siteswith an Editor-selected demo user must return stable403. - Green slices:
GET /api/me, Admin allow/Editor deny for site config and script version mutations, Editor article create and plan approval review action, stable401/403responses, and role-aware frontend navigation.
- Red evidence:
- Command:
docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py - Result: failed as expected because
POST /api/sitesand auth/role checks are not implemented yet. - Output:
F ====================================================================== FAIL: test_editor_cannot_create_target_site_config (__main__.AuthAuthorizationPublicApiTest.test_editor_cannot_create_target_site_config) ---------------------------------------------------------------------- Traceback (most recent call last): File "/app/apps/backend/tests/integration/test_auth_authorization_public_api.py", line 49, in test_editor_cannot_create_target_site_config self.assertEqual(403, response.status_code, response.text) AssertionError: 403 != 404 : {"detail":"Not Found"} ---------------------------------------------------------------------- Ran 1 test in 0.004s FAILED (failures=1)
- Command:
- Green evidence:
- Command:
docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py - Output:
........ ---------------------------------------------------------------------- Ran 8 tests in 0.249s OK
- Command:
- Refactor notes:
- Added local demo auth via
X-Demo-User-Emailusing seeded users. - Kept role constants in domain, current-user/site-config orchestration in application, repository persistence in infrastructure, and FastAPI dependencies/guards in presentation.
- Added minimal plan approval review action endpoint for Task 004 role checks.
- Added FSD role navigation model/component and a deterministic Node test that executes the TypeScript source.
- Regenerated
packages/shared/openapi.jsonandpackages/shared/src/api-types.ts.
- Added local demo auth via
- Verification output:
docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python -m unittest discover apps/backend/tests..............s.... ---------------------------------------------------------------------- Ran 19 tests in 0.364s OK (skipped=1)pnpm --filter @pipeline/frontend test:rolesrole navigation hides Admin-only items for Editorspnpm typecheck@pipeline/shared typecheck: tsc --noEmit @pipeline/frontend typecheck: tsc --noEmitbash tests/smoke/public-health.shbackend health ok runner health ok frontend health ok backend dependencies ok public health smoke ok