Skip to content

RBAC admin UI: user and role management - #594

Closed
kentcdodds wants to merge 4 commits into
cursor/rbac-core-66a6from
cursor/rbac-admin-ui-66a6
Closed

kentcdodds wants to merge 4 commits into
cursor/rbac-core-66a6from
cursor/rbac-admin-ui-66a6

Conversation

@kentcdodds

Copy link
Copy Markdown
Owner

Summary

Phase 2 of the RBAC plan (stacked on the core PR; implemented by a composer 2.5 subagent).

  • /admin route group: /admin/users (paginated list, assign/remove roles), /admin/roles (read-only roles + permissions view), with .json APIs guarded per-action by requireUserWithPermission and HTML shells by requireUserWithRole('admin').
  • Privacy boundary enforced structurally: admin queries select explicit columns from users/user_roles/roles only; the users payload is exactly id, username, email, created_at, updated_at, roles, pinned by a unit shape test so accidental widening fails validate.
  • Last-admin guardrail: removing the admin role from the final admin returns a clear error.
  • Role changes audit-logged via logAuditEvent (category admin).
  • "Admin" nav link rendered only for admins (pure userHasRole on the session payload; server re-checks everything).
  • Playwright E2E (e2e/admin-rbac.spec.ts) with new assignRole / seedE2eUser fixtures: non-admin 403 + hidden nav link, admin role assignment round-trip, metadata-only visibility for a user who owns a seeded secret.

Admin users page (metadata only)
Last-admin guardrail error

System recap — extends app-ui with guarded admin routes (medium risk)

Mode: recap · Base: cursor/rbac-core-66a6 · Head: 67b7a49

Classification: extends — new admin surface composed from the rbac guards introduced in the base PR.

Primitives touched

Primitive Group Impact
app-ui surfaces extends — /admin/users, /admin/roles + JSON APIs
rbac auth composes — first consumers of the request guards

Invariants

Touches per-user-isolation: this is where access='any' is first honored — restricted to account metadata (users, roles). Admin queries never join content tables; a shape test pins the payload.

Testing

  • ✅ npm run validate (all six checks green; 370 unit tests, smoke + admin-rbac E2E)
  • ✅ Full GUI walkthrough recorded on the integration PR: admin login, role assignment/removal, guardrail error, non-admin 403
Open in Web Open in Cursor 

Implement /admin/users and /admin/roles with server shells, JSON APIs,
client routes, role assignment/removal with last-admin guardrail, audit
logging, privacy-boundary shape tests, and Playwright E2E coverage.
Avoid /auth signup rate limits in shared E2E runs by seeding fixture
users through the wrangler D1 wrapper and using login-only auth.
@coderabbitai

coderabbitai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 82717a44-4b56-4c9f-a99d-b264ffac88e3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/rbac-admin-ui-66a6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kody-bot
kody-bot marked this pull request as ready for review July 3, 2026 05:24
@kody-bot

kody-bot commented Jul 3, 2026

Copy link
Copy Markdown
Collaborator

Superseded by #596, which combines the full RBAC stack (proposal, core, admin UI, privacy page, MCP context, and docs) into a single PR targeting main.

@kody-bot kody-bot closed this Jul 3, 2026
@kody-bot
kody-bot deleted the cursor/rbac-admin-ui-66a6 branch July 21, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants