feat(authz): implement permission validation in library update page - #3202
feat(authz): implement permission validation in library update page#3202dcoa wants to merge 5 commits into
Conversation
|
Thanks for the pull request, @dcoa! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. 🔘 Update the status of your PRYour PR is currently marked as a draft. After completing the steps above, update its status by clicking "Ready for Review", or removing "WIP" from the title, as appropriate. Where can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #3202 +/- ##
==========================================
+ Coverage 95.92% 95.93% +0.01%
==========================================
Files 1397 1397
Lines 33581 33619 +38
Branches 7947 7955 +8
==========================================
+ Hits 32214 32254 +40
+ Misses 1308 1307 -1
+ Partials 59 58 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
3ddbedb to
763a073
Compare
763a073 to
1011aab
Compare
Description
This PR continues the authz implementation by adding validations in Library Updates page, where Course Auditor should have read only permissions. Mainwhile other roles (Editor, Staff and Admin) has full manage access.
Important
This PR depends on openedx/openedx-platform#39009 and #3193 and openedx/openedx-authz#417
Supporting information
It closes openedx/openedx-authz#319
Design link
Changes
Navigation
src/header/hooks.tsx— the "Libraries" content-menu entry is gated oncanViewLibraryUpdatesinstead ofcanManageLibraryUpdates.Libraries page (
src/course-libraries/)CourseLibraries.tsx—PermissionDeniedAlertis now driven bycanViewLibraryUpdates;the "Review Updates" header action only renders with
canManageLibraryUpdates, andreadOnlyis threaded down toReviewTabContentandOutOfSyncAlert.OutOfSyncAlert.tsx— newreadOnlyprop that swaps the alert title for a wording thatdoesn't promise an action the user can't take ("Review updates to see what changed" instead
of "…to accept or ignore changes"). The Review button stays, since reviewing is read-only.
ReviewTabContent.tsx— per-item actions were extracted into arenderActionscallback;under
readOnlyonly "Review" is rendered, while "Ignore" and "Update" are omitted.Course outline (
src/course-outline/page-alerts/PageAlerts.jsx)readOnlytoOutOfSyncAlert. The alertis withheld while permissions are loading so it never flashes the read-only wording before
settling on the manage wording.
Preview changes modal (
src/course-unit/preview-changes/index.tsx)canManageLibraryUpdates. For read-only users the accept/ignore (and theupdate/keep variants for text blocks with local changes) buttons are
disabledand wrappedin an
OverlayTriggerpopover explaining why. The two button variants were hoisted intoacceptButton/ignoreButtonlocals so the enabled and read-only footers share them.Testing instructions
enable_authz_course_authoringwaffle flag.course_auditoras roleCourse outline - Course Auditor

Library Updates - Course Auditor
Out of sync Alert - Enabled roles
Best Practices Checklist
We're trying to move away from some deprecated patterns in this codebase. Please
check if your PR meets these recommendations before asking for a review:
.ts,.tsx).propTypesanddefaultPropsin any new or modified code.src/testUtils.tsx(specificallyinitializeMocks)apiHooks.tsin this repo for examples.messages.tsfiles have adescriptionfor translators to use.../in import paths. To import from parent folders, use@src, e.g.import { initializeMocks } from '@src/testUtils';instead offrom '../../../../testUtils'