Files
content-factory/tasks/004-auth-and-admin-editor-roles.md
T

2.1 KiB

Task 004: Auth And Admin/Editor Roles

Development description: Implement simple internal authentication and role-based authorization for the two v1 roles: Admin and Editor.

Implementation Details

  • Add a local-demo authentication mode suitable for Docker Compose:
    • Header-based user selection for local demo, or
    • Session login with seeded users.
  • Enforce role checks at backend endpoint boundaries.
  • Role capabilities:
    • Admin can edit target sites, publishing YAML/scripts, prompt versions, and runner profiles.
    • Editor can create and run article pipelines, edit intermediate outputs, approve content, and create publish commits.
  • Add frontend role-aware navigation:
    • Admin sees site configuration and script versioning screens.
    • Editor sees pipeline execution and review screens.
  • Ensure authorization failures return stable 403 responses.

Public Interface

  • Backend identifies current user and role for each request.
  • Frontend can fetch GET /api/me.
  • Protected endpoints consistently allow or deny Admin/Editor actions.

Acceptance Criteria

  • TDD pre-requirement: before implementation, write one failing public API authorization test for an Editor attempting an Admin-only action; proceed one permission behavior at a time and record red-green evidence in Result.
  • GET /api/me returns the active user and role.
  • Admin can create/update site config and script versions.
  • Editor cannot create/update site config or script versions.
  • Editor can create articles and perform review actions.
  • Unauthorized requests are rejected consistently.
  • Frontend hides Admin-only navigation for Editors.

Verification

  • Run backend authorization tests.
  • Run frontend role rendering tests.
  • Manually verify Admin and Editor demo sessions in Docker Compose.

Result

  • Status: Pending execution.
  • TDD plan: To be filled during execution.
  • Red evidence: To be filled during execution.
  • Green evidence: To be filled during execution.
  • Refactor notes: To be filled during execution.
  • Verification output: To be filled during execution.