Skip to content

fix(frontend): align guild automation access guard - #359

Merged
LucasSantana-Dev merged 1 commit into
mainfrom
fix/rbac-guild-automation-guard-parity
Mar 24, 2026
Merged

LucasSantana-Dev merged 1 commit into
mainfrom
fix/rbac-guild-automation-guard-parity

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • align Guild Automation route and sidebar guards with backend policy by requiring settings:manage
  • add regression tests for route denial and sidebar visibility when only automation access is present
  • update changelog and implementation status notes to reflect RBAC guard parity follow-up

Verification

  • npm run test --workspace=packages/frontend -- src/App.authRoutes.test.tsx src/components/Layout/Sidebar.test.tsx

Summary by CodeRabbit

  • Changed

    • Updated Guild Automation dashboard access controls to require settings:manage permission for both route-level access and sidebar visibility, ensuring UI access aligns with backend authorization and prevents 403 errors.
  • Tests

    • Added tests for Guild Automation route and sidebar visibility based on permission levels.
  • Documentation

    • Updated implementation status for Guild Automation RBAC alignment work.

@vercel

vercel Bot commented Mar 24, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 24, 2026 1:16am

Request Review

@coderabbitai

coderabbitai Bot commented Mar 24, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 3ad8b75e-a0a0-44cb-89a8-66d9bc2248e5

📥 Commits

Reviewing files that changed from the base of the PR and between 70fd7e5 and 515f721.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • docs/IMPLEMENTATION_STATUS.md
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.tsx
📜 Recent review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Quality Gates
  • GitHub Check: SonarCloud Scan
  • GitHub Check: compressed-size
🧰 Additional context used
📓 Path-based instructions (21)
**/*.{js,jsx,ts,tsx,vue,html}

📄 CodeRabbit inference engine (.cursor/rules/accessibility-openness.mdc)

Provide accessible UI components using semantic HTML and ARIA attributes where necessary

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/dependency-injection.mdc)

**/*.{ts,tsx,js,jsx}: Prefer constructor injection for classes that require dependencies
Avoid global mutable singletons unless necessary
Use explicit interfaces for external dependencies to make testing easier

**/*.{ts,tsx,js,jsx}: Include required references in PRs/code for non-trivial logic: TypeScript (official docs), MDN (JavaScript reference), and official docs for any runtime/framework/libraries used (e.g., Node.js, React) as applicable.
Before assuming behavior of an API, include the doc link and a ≤25-word quote when the change relies on it.

**/*.{ts,tsx,js,jsx}: Prefer named exports for clear usage and easier refactors in TypeScript/JavaScript
Keep import order consistent: external first, then internal modules
Remove dead code and unused imports

**/*.{ts,tsx,js,jsx}: Use PascalCase naming convention for React/UI components
Use camelCase naming convention for variables and functions
Use UPPER_SNAKE_CASE naming convention for constants
Maintain consistent import grouping and ordering within the project, keeping third-party imports separate from local imports
For external data sources (HTTP, database), always validate and sanitize input using type guards or schema validators

**/*.{ts,tsx,js,jsx}: Use Prettier with no semicolons, single quotes, 4-space indent, 80 character width
Files must not exceed 250 lines and this is enforced

Implement TypeScript typecheck and linter in CI quality checks

**/*.{ts,tsx,js,jsx}: Use TypeScript for enhanced type safety
Implement error handling and error logging
Avoid commenting code unless extremely necessary - code should explain itself with descriptive names
Leave NO todos, placeholders or missing pieces in the code
Variables and functions must use camelCase
Constants must use UPPER_SNAKE_CASE
Use arrow functions for methods and computed properties
Avoid unnecessary curly braces in conditionals; use concise syntax for simple statements
Maintain consistent import grouping/order: external imports first, then...

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/error-handling.mdc)

**/*.{js,jsx,ts,tsx}: Never throw strings. Throw Error (or typed subclasses) with descriptive messages
Include causal error as cause when available for better debugging
Define clear, stable error codes (e.g., ERR_AUTH_EXPIRED, ERR_NETWORK_TIMEOUT)
Provide optional metadata (e.g., details, retryable, status, correlationId) in error objects
Use domain error classes per area (e.g., AuthenticationError, ValidationError, NetworkError)
Log errors with structure (message, code, stack, cause, correlationId, user context where appropriate)
Mark retryable vs nonRetryable errors where helpful for operations
Set timeouts and handle aborts/cancellations; avoid dangling requests in API/network code
Implement backoff for transient failures; avoid infinite retries
Map HTTP status → domain errors; 4xx vs 5xx behave differently (e.g., retry for 5xx/network)

**/*.{js,jsx,ts,tsx}: Use functional components with hooks in React/React Native. Avoid class components.
Keep components focused on a single responsibility; extract complex logic into custom hooks.
Keep state local when possible. Use Context/Zustand/Redux only when necessary for state management.
If props or state traverse more than 3 levels, consider using context or a feature-scoped store instead of prop drilling.
Use performance optimization techniques: React.memo, useMemo, useCallback, Suspense (web), and virtualization for long lists; avoid unnecessary re-renders.
Web accessibility: use semantic HTML, labels, focus management, keyboard navigation, and aria-* attributes as needed.
React Native accessibility: use accessibility props (accessible, accessibilityLabel), proper roles and labels.
Identify and extract repetitive UI components proactively to components/ with clear props and minimal coupling.
Web styles: prefer co-located styles or design system tokens; avoid global style leakage.
React Native styles: prefer StyleSheet.create, design tokens, and theme providers; avoid in...

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/error-handling.mdc)

**/*.{jsx,tsx}: Use toasts/snackbars for transient errors; avoid blocking modals for non-critical issues in React/React Native UI
Debounce/suppress duplicate toasts to prevent spam
Provide retry/refresh actions when meaningful (e.g., network failure) in error UI
Use error boundaries for render-time exceptions; show fallback UI in React
Respect accessibility: toasts should be announced (aria-live on web; accessibility hints on React Native)

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

Introduce interfaces at module boundaries to enable testing and substitutions

**/*.{ts,tsx}: Avoid using any type in TypeScript. If unavoidable, use unknown with type guards and justify with a code comment
Prefer interface for defining public object shapes in TypeScript, use type for unions and utility types
Use TypeScript utility types such as Partial, Pick, Omit, Readonly, and Record when appropriate
Use I{Name} naming convention for interfaces in TypeScript
Use T{Name} naming convention for type aliases and utility types in TypeScript

**/*.{ts,tsx}: Functions must be less than 50 lines with cyclomatic complexity less than 10
Do not use any types - ESLint enforces this at error level

**/*.{ts,tsx}: Prefer types over interfaces for most cases
Don't ever use any - type safety always
Avoid enums; use const objects instead
For complex types, create a separate file to declare them and import them
Avoid using any type; if unavoidable, use unknown with type guards and justify with code comment
Prefer interface for public API shapes; use type for unions and utility types
Use TypeScript utility types (Partial, Pick, Omit, Readonly, Record)

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (CLAUDE.md)

packages/frontend/src/**/*.{ts,tsx}: Frontend errors are created by Axios interceptor and should be of type ApiError with status and details from backend
Frontend uses path alias @/ mapped to src/ - use this alias for all imports from the src directory

Do not depend on @lucky/shared package in frontend code; make API calls to backend via configured base URL (env)

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/documentation.mdc)

**/*.{js,ts,tsx,jsx}: Minimize comments in code; explain the 'why' when non-obvious, let code express the 'what' through clear naming
Document trade-offs briefly when deviating from ideal patterns

**/*.{js,ts,tsx,jsx}: Store secrets, ports, and hosts in environment variables (.env, .env.example) and never hardcode them
Avoid redundant or decorative AI comments; code should be self-explanatory and only commented when logic is non-obvious; prefer refactoring over lengthy comments

Never hardcode secrets, IPs, or ports; use .env and docs/ for required configuration variables

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/src/components/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-frontend.mdc)

Organize UI components in packages/frontend/src/components/ directory

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/src/{components,pages}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-frontend.mdc)

Use React functional components and hooks; keep components small and focused

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/src/{components,pages}/**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/lucky-frontend.mdc)

Follow existing styling approach (e.g., Tailwind if present); avoid inline styles for layout and theming

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/**

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

The frontend package uses React with Vite and must not depend on the shared package

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/[A-Z]*.{ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

Components must use PascalCase naming

Files:

  • packages/frontend/src/components/Layout/Sidebar.tsx
  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/docs/**/*.{md,mdx}

📄 CodeRabbit inference engine (.cursor/rules/documentation.mdc)

**/docs/**/*.{md,mdx}: Keep API documentation in sync with code changes
Document significant architectural design choices

Files:

  • docs/IMPLEMENTATION_STATUS.md
{CHANGELOG.md,docs/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Update CHANGELOG.md and relevant docs/ files when behavior or setup changes

Files:

  • docs/IMPLEMENTATION_STATUS.md
  • CHANGELOG.md
{CHANGELOG.md,README.md}

📄 CodeRabbit inference engine (.cursor/rules/agent-rules.mdc)

ALWAYS update CHANGELOG.md and README.md as changes are made.

Files:

  • CHANGELOG.md
CHANGELOG.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

CHANGELOG.md must be updated with all changes in pull requests

Always update CHANGELOG.md with all code changes

Update CHANGELOG.md with all changes, include breaking changes documentation, and reference issues and PRs

Files:

  • CHANGELOG.md
**/*.{test,spec}.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/frontend.mdc)

**/*.{test,spec}.{js,jsx,ts,tsx}: Test behavior, not implementation. Prefer Testing Library utilities for testing React/React Native components.
For React Native tests: mock native modules and test component interactions and accessibility labels.

Files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

**/*.{test,spec}.{ts,tsx,js,jsx}: Test behavior, not implementation details
Prefer unit tests for core logic; add integration tests at meaningful boundaries

Files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{test,spec}.{js,ts,jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

**/*.{test,spec}.{js,ts,jsx,tsx}: Use Jest + a React testing library for unit and component tests as applicable
Test behavior, not implementation details

Files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
**/*.{spec,test}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/quality.mdc)

**/*.{spec,test}.{ts,tsx,js,jsx}: Use Jest for unit and integration tests
Test behavior, not implementation details
Run unit, integration tests, and coverage report in CI quality checks

Files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
packages/frontend/src/{main,App}.tsx

📄 CodeRabbit inference engine (.cursor/rules/lucky-frontend.mdc)

Entry point for the Lucky Frontend React app is packages/frontend/src/main.tsx which connects to App.tsx

Files:

  • packages/frontend/src/App.tsx
🧠 Learnings (12)
📚 Learning: 2026-03-15T21:57:49.951Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-15T21:57:49.951Z
Learning: Update `CHANGELOG.md` and relevant `docs/` files when behavior or setup changes

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-14T23:38:59.386Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:38:59.386Z
Learning: Update `CHANGELOG.md` and relevant `docs/` when behavior or setup changes

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to {CHANGELOG.md,docs/**} : Update `CHANGELOG.md` and relevant `docs/` files when behavior or setup changes

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-09T20:20:38.694Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.694Z
Learning: Applies to packages/backend/src/routes/**/*.{ts,tsx} : Structure routes in `packages/backend/src/routes/` directory with separate files for auth, guilds, toggles, and index routes

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to {packages/*/tests/**/*.test.{js,ts},tests/**/*.test.{js,ts}} : Add or adjust unit and integration tests when changing behavior; follow existing patterns in `packages/*/tests` and root `tests/` directories

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
📚 Learning: 2026-03-09T20:20:38.694Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.694Z
Learning: Applies to packages/backend/tests/**/*.{ts,tsx} : Organize tests in `packages/backend/tests/` with unit tests under `unit/` and integration tests under `integration/`, following existing patterns with fixtures and setup

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
📚 Learning: 2026-03-09T20:20:56.356Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-frontend.mdc:0-0
Timestamp: 2026-03-09T20:20:56.356Z
Learning: Applies to packages/frontend/tests/**/*.{ts,tsx,js} : Write tests in `packages/frontend/tests/` using existing test patterns (e.g., Playwright for e2e if configured)

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
📚 Learning: 2026-03-09T20:21:31.459Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.459Z
Learning: Applies to tests/**/*.test.{ts,tsx,js,jsx} : Add integration tests where appropriate

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/components/Layout/Sidebar.test.tsx
📚 Learning: 2026-03-09T20:21:58.991Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.991Z
Learning: Write unit and integration tests in `packages/frontend/tests`; use Playwright for E2E tests when changing user flows

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
📚 Learning: 2026-03-09T20:21:38.098Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.098Z
Learning: Applies to packages/backend/tests/**/*.ts : Follow existing patterns for unit and integration tests in `packages/backend/tests/`

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
📚 Learning: 2026-03-09T20:20:56.356Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-frontend.mdc:0-0
Timestamp: 2026-03-09T20:20:56.356Z
Learning: Applies to packages/frontend/src/pages/**/*.{ts,tsx} : Organize pages in `packages/frontend/src/pages/` directory (e.g., Login, Dashboard, Config, Features, ServersPage)

Applied to files:

  • packages/frontend/src/App.authRoutes.test.tsx
  • packages/frontend/src/App.tsx
📚 Learning: 2026-03-09T20:21:31.459Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.459Z
Learning: Applies to **/*.{spec,test}.{ts,tsx,js,jsx} : Test behavior, not implementation details

Applied to files:

  • packages/frontend/src/components/Layout/Sidebar.test.tsx
🔇 Additional comments (13)
CHANGELOG.md (1)

16-18: LGTM!

The changelog entry accurately documents the RBAC guard alignment for Guild Automation, explaining both the route and sidebar visibility changes and the user-facing impact (preventing 403 responses from false-positive UI access).

docs/IMPLEMENTATION_STATUS.md (1)

108-108: LGTM!

The updated description accurately reflects the nature of this PR's work (route/sidebar guard parity) and maintains proper tracking of the RBAC alignment effort.

packages/frontend/src/components/Layout/Sidebar.test.tsx (2)

41-48: LGTM!

The typed ACCESS_NONE constant is a good pattern for test maintainability, ensuring consistent baseline access state across tests.


351-394: Well-structured regression tests.

These tests correctly validate that the Guild Automation nav item requires settings: 'manage' access:

  • The negative case (lines 351-372) proves that having automation: 'manage' alone is insufficient when settings is only 'view'.
  • The positive case (lines 374-394) confirms visibility when settings: 'manage' is granted.

This provides good coverage for the sidebar filtering logic changes.

packages/frontend/src/App.authRoutes.test.tsx (2)

39-41: LGTM!

The mock follows the established pattern used for other page mocks in this test file.


270-297: Thorough route guard regression test.

This test correctly validates the updated /guild-automation route guard:

  • Demonstrates that automation: 'manage' alone is insufficient when settings is only 'view'
  • Verifies the correct "Access denied" state and the permission message referencing the settings module
  • Confirms the page component is not rendered

This provides good regression coverage for the RBAC guard parity changes.

packages/frontend/src/components/Layout/Sidebar.tsx (4)

36-45: LGTM!

The NavItem interface extension with optional requiredMode provides flexibility for per-item access requirements while maintaining backward compatibility through the default 'view' mode in canViewModule.


121-126: Correct alignment with backend policy.

Changing Guild Automation from module: 'automation' to module: 'settings' with requiredMode: 'manage' properly aligns the sidebar visibility with the route guard and backend authorization requirements.


212-218: Clean function extension.

The canViewModule function cleanly passes through the requiredMode parameter to hasModuleAccess, which handles the hierarchical access semantics ('manage' satisfies both 'view' and 'manage' requirements).


430-436: LGTM!

The filter correctly passes each item's requiredMode to enable per-item access mode enforcement.

packages/frontend/src/App.tsx (3)

67-96: LGTM!

The RouteModuleGuard component is cleanly extended with the optional requiredMode prop, maintaining backward compatibility via the 'view' default while enabling stricter access requirements where needed.


98-108: Clean helper extension.

The guardedRoute helper maintains its ergonomic API while adding the optional requiredMode parameter, keeping route definitions concise.


158-165: Correct alignment with backend policy.

The /guild-automation route now properly requires settings:manage access, matching the backend authorization policy and preventing the 403 responses that occurred when users had automation access but lacked settings:manage.


📝 Walkthrough

Walkthrough

The PR updates Guild Automation dashboard access controls to require settings:manage permission instead of the default view mode. Changes include configurable permission modes in route guards and sidebar navigation filtering, with corresponding test additions and documentation updates reflecting the RBAC enforcement.

Changes

Cohort / File(s) Summary
Documentation
CHANGELOG.md, docs/IMPLEMENTATION_STATUS.md
Updated changelog entry documenting the Guild Automation access control requirement change, and refreshed implementation status to reflect ongoing RBAC parity work.
Route Access Control
packages/frontend/src/App.tsx, packages/frontend/src/App.authRoutes.test.tsx
Extended RouteModuleGuard and guardedRoute helper to support configurable requiredMode parameter (defaulting to 'view'). Updated /guild-automation route to require 'manage' mode for 'settings' module. Added test case verifying access denial when user lacks settings:manage permission.
Sidebar Navigation
packages/frontend/src/components/Layout/Sidebar.tsx, packages/frontend/src/components/Layout/Sidebar.test.tsx
Enhanced NavItem to accept optional requiredMode property. Updated "Guild Automation" item to use settings module with 'manage' mode. Modified canViewModule helper to accept and apply requiredMode when filtering visibility. Added tests validating conditional rendering based on permission level.

Sequence Diagram(s)

sequenceDiagram
    actor User
    participant RouteModule as RouteModuleGuard
    participant Sidebar
    participant RBAC as hasModuleAccess<br/>(Permission Check)
    participant Page as Guild Automation<br/>Page

    User->>RouteModule: Request /guild-automation
    RouteModule->>RBAC: hasModuleAccess(effectiveAccess,<br/>'settings', 'manage')
    alt Has settings:manage
        RBAC-->>RouteModule: ✓ Access granted
        RouteModule->>Page: Render page
        Page-->>User: Guild Automation UI
    else Lacks settings:manage
        RBAC-->>RouteModule: ✗ Access denied
        RouteModule-->>User: Access Denied screen
    end

    User->>Sidebar: Render navigation
    Sidebar->>RBAC: For each NavItem:<br/>hasModuleAccess(effectiveAccess,<br/>item.module, item.requiredMode)
    alt Has required permission
        RBAC-->>Sidebar: ✓ Include item
        Sidebar-->>User: "Guild Automation" visible
    else Lacks required permission
        RBAC-->>Sidebar: ✗ Exclude item
        Sidebar-->>User: "Guild Automation" hidden
    end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'fix(frontend): align guild automation access guard' directly summarizes the main change: aligning frontend access guards for guild automation to require the correct permission level. It is specific, clear, and accurately reflects the primary objective of the changeset.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/rbac-guild-automation-guard-parity

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

Size Change: +33 B (+0.01%)

Total Size: 318 kB

Filename Size Change
packages/frontend/dist/assets/AutoMessages-DVjTBVCN.js 0 B -2.51 kB (removed) 🏆
packages/frontend/dist/assets/AutoMod-BNHWrDvl.js 0 B -3.64 kB (removed) 🏆
packages/frontend/dist/assets/CommandsConfig-CJNxgZX6.js 0 B -1.48 kB (removed) 🏆
packages/frontend/dist/assets/Config-DkWVtOBD.js 0 B -1.7 kB (removed) 🏆
packages/frontend/dist/assets/DashboardOverview-BJtn__RI.js 0 B -3.09 kB (removed) 🏆
packages/frontend/dist/assets/EmbedBuilder-CUMvEtqD.js 0 B -3.33 kB (removed) 🏆
packages/frontend/dist/assets/Features-BkG7o31x.js 0 B -2.84 kB (removed) 🏆
packages/frontend/dist/assets/GuildAutomation-DQDZZVpO.js 0 B -2.92 kB (removed) 🏆
packages/frontend/dist/assets/index-7BZyJcXi.js 0 B -26.7 kB (removed) 🏆
packages/frontend/dist/assets/label-C6Yry4eD.js 0 B -487 B (removed) 🏆
packages/frontend/dist/assets/Levels-B5pNgyiL.js 0 B -2.63 kB (removed) 🏆
packages/frontend/dist/assets/Login-BYpafyH3.js 0 B -2.81 kB (removed) 🏆
packages/frontend/dist/assets/Lyrics-g5tLWQi9.js 0 B -1.33 kB (removed) 🏆
packages/frontend/dist/assets/Moderation-Bxz6jZQM.js 0 B -4.39 kB (removed) 🏆
packages/frontend/dist/assets/Music-CDokgzmY.js 0 B -6.23 kB (removed) 🏆
packages/frontend/dist/assets/MusicConfig-Dx3WLYTf.js 0 B -1.6 kB (removed) 🏆
packages/frontend/dist/assets/ReactionRoles-B_JD--NA.js 0 B -1.89 kB (removed) 🏆
packages/frontend/dist/assets/ServerLogs-BzngmUGU.js 0 B -2.9 kB (removed) 🏆
packages/frontend/dist/assets/ServerSettings-1G6kXhfT.js 0 B -4.16 kB (removed) 🏆
packages/frontend/dist/assets/ServersPage-DJ-BsVrC.js 0 B -2.75 kB (removed) 🏆
packages/frontend/dist/assets/Starboard-CX9WCqgk.js 0 B -2.08 kB (removed) 🏆
packages/frontend/dist/assets/TrackHistory-uo1SZDJf.js 0 B -1.88 kB (removed) 🏆
packages/frontend/dist/assets/TwitchNotifications-CK7jCmyS.js 0 B -2.25 kB (removed) 🏆
packages/frontend/dist/assets/AutoMessages-1ZIvOQrm.js 2.51 kB +2.51 kB (new file) 🆕
packages/frontend/dist/assets/AutoMod-Bbf7bC1y.js 3.64 kB +3.64 kB (new file) 🆕
packages/frontend/dist/assets/CommandsConfig-Bc1jZnPq.js 1.48 kB +1.48 kB (new file) 🆕
packages/frontend/dist/assets/Config-C0K-nd8u.js 1.7 kB +1.7 kB (new file) 🆕
packages/frontend/dist/assets/DashboardOverview-BQ4oEMnf.js 3.09 kB +3.09 kB (new file) 🆕
packages/frontend/dist/assets/EmbedBuilder-CqXnduLT.js 3.33 kB +3.33 kB (new file) 🆕
packages/frontend/dist/assets/Features-4JbR4LE8.js 2.85 kB +2.85 kB (new file) 🆕
packages/frontend/dist/assets/GuildAutomation-zovwBJs7.js 2.92 kB +2.92 kB (new file) 🆕
packages/frontend/dist/assets/index-Bk2THLeI.js 26.8 kB +26.8 kB (new file) 🆕
packages/frontend/dist/assets/label-BEsyb6lb.js 489 B +489 B (new file) 🆕
packages/frontend/dist/assets/Levels-CeJffXhY.js 2.63 kB +2.63 kB (new file) 🆕
packages/frontend/dist/assets/Login-CXPFv27W.js 2.82 kB +2.82 kB (new file) 🆕
packages/frontend/dist/assets/Lyrics-Bew56Y6k.js 1.33 kB +1.33 kB (new file) 🆕
packages/frontend/dist/assets/Moderation-DtVD-nX-.js 4.38 kB +4.38 kB (new file) 🆕
packages/frontend/dist/assets/Music-DhbwiE0z.js 6.23 kB +6.23 kB (new file) 🆕
packages/frontend/dist/assets/MusicConfig-Bqhvq5nO.js 1.6 kB +1.6 kB (new file) 🆕
packages/frontend/dist/assets/ReactionRoles-CzJlFFDM.js 1.89 kB +1.89 kB (new file) 🆕
packages/frontend/dist/assets/ServerLogs-Dwlq5lU8.js 2.9 kB +2.9 kB (new file) 🆕
packages/frontend/dist/assets/ServerSettings-Dvgl7spA.js 4.16 kB +4.16 kB (new file) 🆕
packages/frontend/dist/assets/ServersPage-DfXAKf3z.js 2.75 kB +2.75 kB (new file) 🆕
packages/frontend/dist/assets/Starboard-X-vXqwNr.js 2.08 kB +2.08 kB (new file) 🆕
packages/frontend/dist/assets/TrackHistory-D8ACHH4j.js 1.88 kB +1.88 kB (new file) 🆕
packages/frontend/dist/assets/TwitchNotifications-DlcAUzn5.js 2.25 kB +2.25 kB (new file) 🆕
ℹ️ View Unchanged
Filename Size
packages/frontend/dist/assets/ActionPanel-IlTQQdBi.js 399 B
packages/frontend/dist/assets/api-3qPvg92E.js 2.9 kB
packages/frontend/dist/assets/authStore-DqBjQ5Zu.js 556 B
packages/frontend/dist/assets/badge-UHT_X0Y7.js 502 B
packages/frontend/dist/assets/Card-DkW3SlEf.js 529 B
packages/frontend/dist/assets/CustomCommands-A5LRuyG5.js 2.15 kB
packages/frontend/dist/assets/guildStore-BuJ9Xfyw.js 794 B
packages/frontend/dist/assets/index-C-s2muDZ.css 15.8 kB
packages/frontend/dist/assets/input-DEJ6GGvd.js 466 B
packages/frontend/dist/assets/LastFm-BiamMFPW.js 1.73 kB
packages/frontend/dist/assets/PrivacyPolicy-ono5KELP.js 1.38 kB
packages/frontend/dist/assets/rolldown-runtime-COnpUsM8.js 467 B
packages/frontend/dist/assets/SectionHeader-BLhRbHHF.js 384 B
packages/frontend/dist/assets/select-C-42XbVD.js 1.22 kB
packages/frontend/dist/assets/Skeleton-qubvjXlZ.js 235 B
packages/frontend/dist/assets/switch-DQhtgnVB.js 542 B
packages/frontend/dist/assets/TermsOfService-q5ySuxzZ.js 1.37 kB
packages/frontend/dist/assets/usePageMetadata--GZBG1v_.js 327 B
packages/frontend/dist/assets/utils-CQOjf6Xw.js 147 B
packages/frontend/dist/assets/vendor-forms-KXRApnAU.js 25.4 kB
packages/frontend/dist/assets/vendor-radix-Uy8m4UkR.js 33.5 kB
packages/frontend/dist/assets/vendor-react-DllCF3mE.js 55.6 kB
packages/frontend/dist/assets/vendor-state-BC0s6PNN.js 22 kB
packages/frontend/dist/assets/vendor-ui-BaQss6NY.js 64.1 kB

compressed-size-action

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit 4e5be9c into main Mar 24, 2026
13 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/rbac-guild-automation-guard-parity branch March 24, 2026 01:21

This branch was successfully deployed

1 active deployment
Preview — 515f721a Deployed Mar 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant