feat(permissions): add permission manifest constant, types utilities, my-org tarball#418
feat(permissions): add permission manifest constant, types utilities, my-org tarball#418grandmaester wants to merge 5 commits into
Conversation
📝 WalkthroughWalkthroughAdds MyOrganization permission manifests, query keys, API types, public exports, and React utilities for permission checks and tier calculation. Core now consumes the packaged SDK tarball locally, and the utilities include Vitest coverage. ChangesMyOrganization permissions
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai Review the PR changes |
|
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/core/package.json`:
- Line 55: Update the `@auth0/myorganization-js` dependency in packages/core so
the published package does not reference the repository-relative file: archive;
use the appropriate registry version or ensure packaging rewrites it to a
consumer-available dependency.
In `@packages/react/src/lib/utils/my-organization/permission-utils.ts`:
- Around line 65-73: Update getResourceVerbs to recognize only permissions with
exactly three segments matching <verb>:my_org:<resource>; require the namespace
segment to be my_org and reject trailing segments or other namespaces before
adding the verb.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 43807a54-afdf-4022-9646-d1e292e5f070
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (9)
auth0-myorganization-js-1.1.0.tgzpackages/core/package.jsonpackages/core/src/services/my-organization/index.tspackages/core/src/services/my-organization/permissions/index.tspackages/core/src/services/my-organization/permissions/permission-manifest.tspackages/core/src/services/my-organization/permissions/permission-query-keys.tspackages/core/src/services/my-organization/permissions/permission-types.tspackages/react/src/lib/utils/my-organization/__tests__/permission-utils.test.tspackages/react/src/lib/utils/my-organization/permission-utils.ts
| const verbs = getResourceVerbs(userPermissions, resource); | ||
|
|
||
| if (verbs.has('delete')) { | ||
| return 'admin'; |
There was a problem hiding this comment.
admin can have all create, update and delete scopes right
Summary
Foundation for permission-based UI gating: adds the MyOrganization SDK with the
GET /user-permissionsAPI, plus the type-safe permission manifest, query keys, types, and pure permission-checking utilities.This is PR 1 of 3 for the Permission Gating Implementation.
Follow-ups: (2)
PermissionProvidercontext +usePermissionshook, (3)PermissionDeniedTooltipand wiring.Why
Components currently gate mutations with a coarse binary
readOnlyprop. The MyOrganization API exposes granular per-resource permissions, so we're moving to fine-grained checks. This approach is a centralized Permission Manifest Provider fetched eagerly at app init. This PR lands the manifest and utilities that everything else builds on.What
packages/core— newservices/my-organization/permissions/module:permission-manifest.ts—PERMISSION_MANIFEST(~29 permissions, grouped by resource) and the derivedMyOrgPermissionunion type.permission-query-keys.ts—permissionQueryKeysfor React Query cache management (mirrorsconfigQueryKeys).permission-types.ts— request/response aliases from the SDK plus thePermissionTiertype ('admin' | 'editor' | 'viewer').permission-utils.ts:hasPermission,hasAnyPermission,hasAllPermissions— type-safe checks over the flat permission list.getUserTier(permissions, resource)— derives the behavior tier from the action verbs held for a resource (delete→ admin,create/update→ editor, else viewer). Resource segments are matched exactly, so sub-resources (e.g.member_roles,memberships) are tiered independently.Dependency — vendored
auth0-myorganization-js@1.1.0tarball (includes theGET /user-permissionsendpoint) and installed it. [To be Removed later once package is released on registry]Packages
packages/corepackages/reactexamplesTesting
Unit tests cover the utilities exhaustively (presence/absence, empty-list vacuous truth, all four tier outcomes, and resource-segment edge cases such as
membersvsmembershipsand sub-resource independence). Pure functions and constants only — no runtime/UI behavior in this PR.Checklist
Contributing