Skip to content

US-32 - Enforce role-based access on trip features #133

@vmillet-dev

Description

@vmillet-dev

User Story

As a product owner, I want each trip feature to be accessible only to the appropriate role, so that the integrity of the planning process is maintained.

Acceptance Criteria

  • All permissions defined in the spec rights matrix are enforced both client-side (UI) and server-side (API)
  • Read-only visitors cannot vote, comment, select listings, or view member availability
  • Members cannot reveal the podium, configure budget settings, or invite other members
  • The organiser cannot leave their own trip

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions