Skip to content

Add recipe:publish permission and admin publication endpoints #1135

Description

@dgee2

Goal

Allow users with the recipe:publish permission to publish and unpublish recipes, making them visible at their public slug URL.

Spec reference

docs/specs/recipe-creation-target-architecture.md — §"Access and publication model – Admin publication control"

Implementation notes

  • Auth0 permission recipe:publish; add a corresponding ASP.NET Core authorization policy
  • PUT /api/recipe/{recipeId}/publication (admin only):
    • Publish action: creates or reactivates RecipePublication row with generated slug; emits RecipePublished outbox event
    • Unpublish action: sets UnpublishedAtUtc/UnpublishedByUserId; emits RecipeUnpublished outbox event
    • Request body: { action: "publish" | "unpublish" }
  • Extend search projection consumer (from E5.4) to handle RecipePublished and RecipeUnpublished events: update IsPublishedExternally field on RecipeSearchIndex row
  • 403 for callers without recipe:publish; 404 if recipe not found

Acceptance criteria

  • Publish creates RecipePublication row and emits outbox event
  • Unpublish sets UnpublishedAtUtc and emits outbox event
  • RecipeSearchIndex.IsPublishedExternally updated by consumer after event processed
  • Non-admin 403

Testing

  • Integration tests: publish success, unpublish success, non-admin 403
  • Integration test: search index IsPublishedExternally updated after consumer cycle

Part of#1103

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    .NETPull requests that update .net codeenhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions