RBAC admin UI: user and role management - #594
kentcdodds wants to merge 4 commits into
Conversation
Implement /admin/users and /admin/roles with server shells, JSON APIs, client routes, role assignment/removal with last-admin guardrail, audit logging, privacy-boundary shape tests, and Playwright E2E coverage.
Avoid /auth signup rate limits in shared E2E runs by seeding fixture users through the wrangler D1 wrapper and using login-only auth.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by #596, which combines the full RBAC stack (proposal, core, admin UI, privacy page, MCP context, and docs) into a single PR targeting main. |
Summary
Phase 2 of the RBAC plan (stacked on the core PR; implemented by a composer 2.5 subagent).
/adminroute group:/admin/users(paginated list, assign/remove roles),/admin/roles(read-only roles + permissions view), with.jsonAPIs guarded per-action byrequireUserWithPermissionand HTML shells byrequireUserWithRole('admin').users/user_roles/rolesonly; the users payload is exactlyid, username, email, created_at, updated_at, roles, pinned by a unit shape test so accidental widening failsvalidate.logAuditEvent(categoryadmin).userHasRoleon the session payload; server re-checks everything).e2e/admin-rbac.spec.ts) with newassignRole/seedE2eUserfixtures: non-admin 403 + hidden nav link, admin role assignment round-trip, metadata-only visibility for a user who owns a seeded secret.System recap — extends app-ui with guarded admin routes (medium risk)
Mode: recap · Base:
cursor/rbac-core-66a6· Head:67b7a49Classification: extends — new admin surface composed from the rbac guards introduced in the base PR.
Primitives touched
app-ui/admin/users,/admin/roles+ JSON APIsrbacInvariants
Touches
per-user-isolation: this is whereaccess='any'is first honored — restricted to account metadata (users, roles). Admin queries never join content tables; a shape test pins the payload.Testing
npm run validate(all six checks green; 370 unit tests, smoke + admin-rbac E2E)