Repository navigation
Farm configuration and identity become Owner-only, matching spec §5.1 #729
Description
Activity
- addedsliceThin vertical work itemThin vertical work itemarea:apiAPI/endpoint layerAPI/endpoint layerarea:frontendReact/Vite web clientReact/Vite web clientsize:MA day or two; migration or a multi-state UIA day or two; migration or a multi-state UIpriority:tier3Real product weight, real costReal product weight, real cost
on Sep 8, 2026 Triaged in the 2026-09-13 issue cleanup. Kept open, labelled
priority:tier3("real product weight, real cost").Why it stays open: it closes a genuine code-vs-spec divergence, and the spec is the authority. §5.1 gives Manager "Farm operations, inventory, health, reports"; configuration is not in that list. The broader reading exists only as a code comment in
AuthPolicies.cswritten for #103 — an interpretation, never a decision anyone recorded. Today a Manager can change the farm's currency, timezone, locale, unit system, date and time formats, first day of week, default stepper unit and the worker sale allocation policy.Why tier3 and not higher: the farm running this deployment has a trusted Manager, so nothing is being exploited. It is a divergence to resolve, not an incident to contain.
Two things for whoever picks it up:
- Either direction closes the divergence, and the issue argues only one of them. Amending §5.1 to say Manager may configure is also a valid resolution, and it is a one-file docs change. Tier3 was chosen on the assumption that the spec is right and the code drifted — if that assumption is wrong, say so on this issue rather than implementing against it.
- The body is honest about the cost and it is worth re-reading before starting: a Manager would no longer be able to correct a wrong timezone without an Owner. On a farm whose Owner is not at a desk, that is a real operational change, not a paperwork one.
Scope is unchanged and fully enumerated in the body:
AccountEndpoints.csGET/PUT /settings,FarmLogoEndpoints.cs,FarmBannerEndpoints.cs,nav.tsx:79(therole === "Admin"pattern already exists atnav.tsx:88), the §5.1 amendment, and a decision record — #103 set the current gate deliberately, so without a record a future reader will assume this drifted.The out-of-scope note also stands: the other 33
AuthPolicies.AdminOnlycall sites stay where they are. This is about configuration and identity, not the whole tier.- added a commit that references this issue
on Oct 3, 2026
What
Move the farm settings screen, the farm logo and the farm banner from the
AdminOnlytier (Owner or Manager) toOwnerOnly.Why
The spec already says this.
specs/product/specs.md§5.1 defines the roles as:| Owner | Full access |
| Manager | Farm operations, inventory, health, reports |
Configuration is not in Manager's list. The broader reading lives only in a code
comment in
AuthPolicies.cswritten for #103 — "Manager → corrective actions,config, money" — which is an interpretation, not the spec. Today
GET/PUT /account/settingsareAuthPolicies.AdminOnly(
AccountEndpoints.cs:26,31) andnav.tsx:79mirrors that gate deliberately, soa Manager can change the farm's currency, timezone, locale, unit system and
worker sale allocation policy.
This came up while scoping #727 (a per-farm discount ceiling). That issue no
longer depends on this one — see the decision there — but the question it exposed
is worth settling on its own terms.
Scope
AccountEndpoints.cs—GET /settingsandPUT /settingstoAuthPolicies.OwnerOnly.FarmLogoEndpoints.csandFarmBannerEndpoints.cs— the same move. Includethem. They are farm identity in the same Accounts group; moving settings and
leaving these splits one concept across two tiers for no reason.
nav.tsx:79— gate the Farm settings entry onrole === "Admin"rather thanisAdmin. The pattern already exists atnav.tsx:88for/users, so no newisOwnerhelper is needed.specs/product/specs.md§5.1 — say explicitly that farm configuration isOwner-only, so the table and the code agree.
future reader will assume this drifted.
Out of scope
The other 33
AuthPolicies.AdminOnlycall sites. Flocks, inventory, products,egg grades, reports, daily entries, stock and sales corrections are all genuinely
"farm operations, inventory, health, reports" and stay where they are. This issue
is about configuration and identity, not the whole tier.
What a Manager loses
Farm name, timezone, locale, currency, unit system, date format, time format,
custom date/time formats, first day of week, default stepper unit, worker sale
allocation policy, logo and banner. Worth stating plainly before this ships:
a Manager will no longer be able to correct a wrong timezone without an Owner.
Acceptance
GETandPUT /account/settings, and from the logoand banner endpoints.
— that comes from a separate endpoint (
AccountEndpoints.cs:176), and a testshould pin that it did not regress.
AuthPolicies.csagree in wording.Notes
grep -rln "AdminOnly\|isAdmin" tests/ web/srcreturns 44 files. Most areunrelated to settings, but the role-matrix and admin-gating suites will need the
new expectation, and
FarmSettingsTests.cs(939 lines) andSettingsPage.test.tsx(1307 lines) carry the bulk of the coverage.