2.1 KiB
2.1 KiB
Task 004: Auth And Admin/Editor Roles
Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.
Implementation Details
- Add a local-demo authentication mode suitable for Docker Compose:
- Header-based user selection for local demo, or
- Session login with seeded users.
- Enforce role checks at backend endpoint boundaries.
- Role capabilities:
- Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
- Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
- Add frontend role-aware navigation:
- Admin sees site configuration and script versioning screens.
- Editor sees pipeline execution and review screens.
- Ensure authorization failures return stable
403responses.
Public Interface
- Backend identifies current user and role for each request.
- Frontend can fetch
GET /api/me. - Protected endpoints consistently allow or deny Admin/Editor actions.
Acceptance Criteria
- TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in
Result. GET /api/mereturns the active user and role.- Admin can create/update site config and script versions.
- Editor cannot create/update site config or script versions.
- Editor can create articles and perform review actions.
- Unauthorized requests are rejected consistently.
- Frontend hides Admin-only navigation for Editors.
Verification
- Run backend authorization tests.
- Run frontend role rendering tests.
- Manually verify Admin and Editor demo sessions in Docker Compose.
Result
- Status: Pending execution.
- TDD plan: To be filled during execution.
- Red evidence: To be filled during execution.
- Green evidence: To be filled during execution.
- Refactor notes: To be filled during execution.
- Verification output: To be filled during execution.