49 lines
2.1 KiB
Markdown
49 lines
2.1 KiB
Markdown
# Task 004: Auth And Admin/Editor Roles
|
|
|
|
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
|
|
|
|
## Implementation Details
|
|
|
|
- Add a local-demo authentication mode suitable for Docker Compose:
|
|
- Header-based user selection for local demo, or
|
|
- Session login with seeded users.
|
|
- Enforce role checks at backend endpoint boundaries.
|
|
- Role capabilities:
|
|
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
|
|
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
|
|
- Add frontend role-aware navigation:
|
|
- Admin sees site configuration and script versioning screens.
|
|
- Editor sees pipeline execution and review screens.
|
|
- Ensure authorization failures return stable `403` responses.
|
|
|
|
## Public Interface
|
|
|
|
- Backend identifies current user and role for each request.
|
|
- Frontend can fetch `GET /api/me`.
|
|
- Protected endpoints consistently allow or deny Admin/Editor actions.
|
|
|
|
## Acceptance Criteria
|
|
|
|
- [ ] TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in `Result`.
|
|
- [ ] `GET /api/me` returns the active user and role.
|
|
- [ ] Admin can create/update site config and script versions.
|
|
- [ ] Editor cannot create/update site config or script versions.
|
|
- [ ] Editor can create articles and perform review actions.
|
|
- [ ] Unauthorized requests are rejected consistently.
|
|
- [ ] Frontend hides Admin-only navigation for Editors.
|
|
|
|
## Verification
|
|
|
|
- Run backend authorization tests.
|
|
- Run frontend role rendering tests.
|
|
- Manually verify Admin and Editor demo sessions in Docker Compose.
|
|
|
|
## Result
|
|
|
|
- Status: Pending execution.
|
|
- TDD plan: To be filled during execution.
|
|
- Red evidence: To be filled during execution.
|
|
- Green evidence: To be filled during execution.
|
|
- Refactor notes: To be filled during execution.
|
|
- Verification output: To be filled during execution.
|