Skip to content

F27: Roles + scoped permissions — role model, flock-scoped workers, RBAC UI (builds on #73) #103

Description

@mforce

Spec §5.1–5.3. Grows the #73 Admin/Worker split into the real role model. #84 (magic strings: role/claim constants, typed SPA statuses) rides along — touching every gate is exactly when to de-string them.

Roles shipped now (spec §5.1)

Role Gates
Owner everything (today's Admin, renamed conceptually; existing Admin role remains the seed)
Manager farm operations + inventory + reports + corrective actions — everything but user management and account-level config
Worker production recording, restricted to assigned flocks (§5.3)
Sales customers, orders, payments — no production writes, no expenses
Read-only dashboards/reports/stock views only

Deferred with rationale (noted in GLOSSARY):

  • Vet/Consultant — there is no health/medication module to gate yet; an ungated role would be Read-only with a misleading name.
  • House-level scoping — houses are not entities yet (houseId is an opaque Guid on entries; spec itself defers real house management). Flock-level scoping ships now; the user_role_assignments shape carries the nullable house_id column per §5.2 so no schema churn later.

Scope

  • Domain/persistence: user_role_assignments per §5.2 (user, role, nullable farm/house/flock scope). Roles stay ASP.NET Identity roles (Owner=Admin seed, + Manager/Sales/ReadOnly); assignments add the scoping dimension.
  • Authz: policy layer maps role → allowed endpoint groups (replacing the binary AdminOnly on the non-money gates; money stays Owner/Manager). Worker flock-scope enforcement in daily-entry/water/feed record paths: assigned-flocks check → 403 with problem body.
  • Tech debt: magic strings — duplicated role/claim constants, untyped SPA status strings #84 batched: role names/claims → constants class; SPA statuses/action codes → typed unions where they exist as strings; audit action codes centralized server-side.
  • API: user management grows role selection (all shipped roles) + flock assignment CRUD for workers (Owner only).
  • SPA: Users page — role picker + worker flock assignments; nav/screen gating per role (Sales sees sales+customers; Read-only sees dashboards/stock/reports).
  • Audit: role/assignment changes audited (User.RoleChange, User.FlockAssignment).
  • Sync: GLOSSARY roles table + Help "Who can do what" rewrite + TOC check.

Tests

  • Full 403 matrix per role × endpoint group (extends AdminGatingTests)
  • Worker flock-scope: assigned flock 201, unassigned flock 403, no-assignment = all flocks (backward compat with F19: Admin-gate corrective/destructive actions — stepping stone to full RBAC #73 workers) or none? → all flocks when no assignment rows exist (grandfathering; explicit assignment narrows)
  • Role changes take effect at token refresh (existing claim mechanism)
  • Tenant isolation on assignments; audit rows for role/assignment changes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions