Files
content-factory/tasks/004-auth-and-admin-editor-roles.md
T

5.1 KiB

Task 004: Auth And Admin/Editor Roles

Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.

Implementation Details

  • Add a local-demo authentication mode suitable for Docker Compose:
    • Header-based user selection for local demo, or
    • Session login with seeded users.
  • Enforce role checks at backend endpoint boundaries.
  • Role capabilities:
    • Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
    • Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
  • Add frontend role-aware navigation:
    • Admin sees site configuration and script versioning screens.
    • Editor sees pipeline execution and review screens.
  • Ensure authorization failures return stable 403 responses.

Public Interface

  • Backend identifies current user and role for each request.
  • Frontend can fetch GET /api/me.
  • Protected endpoints consistently allow or deny Admin/Editor actions.

Acceptance Criteria

  • TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in Result.
  • GET /api/me returns the active user and role.
  • Admin can create/update site config and script versions.
  • Editor cannot create/update site config or script versions.
  • Editor can create articles and perform review actions.
  • Unauthorized requests are rejected consistently.
  • Frontend hides Admin-only navigation for Editors.

Verification

  • Run backend authorization tests.
  • Run frontend role rendering tests.
  • Manually verify Admin and Editor demo sessions in Docker Compose.

Result

  • Status: Completed.
  • TDD plan:
    • First behavior slice: public FastAPI HTTP authorization denial for a demo Editor attempting an Admin-only site configuration mutation.
    • Public API contract selected for local demo auth: X-Demo-User-Email: editor@example.com.
    • Red test: POST /api/sites with an Editor-selected demo user must return stable 403.
    • Green slices: GET /api/me, Admin allow/Editor deny for site config and script version mutations, Editor article create and plan approval review action, stable 401/403 responses, and role-aware frontend navigation.
  • Red evidence:
    • Command: docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py
    • Result: failed as expected because POST /api/sites and auth/role checks are not implemented yet.
    • Output:
      F
      ======================================================================
      FAIL: test_editor_cannot_create_target_site_config (__main__.AuthAuthorizationPublicApiTest.test_editor_cannot_create_target_site_config)
      ----------------------------------------------------------------------
      Traceback (most recent call last):
        File "/app/apps/backend/tests/integration/test_auth_authorization_public_api.py", line 49, in test_editor_cannot_create_target_site_config
          self.assertEqual(403, response.status_code, response.text)
      AssertionError: 403 != 404 : {"detail":"Not Found"}
      
      ----------------------------------------------------------------------
      Ran 1 test in 0.004s
      
      FAILED (failures=1)
      
  • Green evidence:
    • Command: docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python apps/backend/tests/integration/test_auth_authorization_public_api.py
    • Output:
      ........
      ----------------------------------------------------------------------
      Ran 8 tests in 0.249s
      
      OK
      
  • Refactor notes:
    • Added local demo auth via X-Demo-User-Email using seeded users.
    • Kept role constants in domain, current-user/site-config orchestration in application, repository persistence in infrastructure, and FastAPI dependencies/guards in presentation.
    • Added minimal plan approval review action endpoint for Task 004 role checks.
    • Added FSD role navigation model/component and a deterministic Node test that executes the TypeScript source.
    • Regenerated packages/shared/openapi.json and packages/shared/src/api-types.ts.
  • Verification output:
    • docker compose run --rm --build -v /Users/gavrilovdev/tmp/pupline:/app -w /app backend python -m unittest discover apps/backend/tests
      ..............s....
      ----------------------------------------------------------------------
      Ran 19 tests in 0.364s
      
      OK (skipped=1)
      
    • pnpm --filter @pipeline/frontend test:roles
      role navigation hides Admin-only items for Editors
      
    • pnpm typecheck
      @pipeline/shared typecheck: tsc --noEmit
      @pipeline/frontend typecheck: tsc --noEmit
      
    • bash tests/smoke/public-health.sh
      backend health ok
      runner health ok
      frontend health ok
      backend dependencies ok
      public health smoke ok