Skip to content

Wire identity role into Settings UI (admin gate + nav gating) #10

Description

@robpitcher

Background

PR #8 added the identity foundation: GitHub OAuth sign-in plus a per-session login + role (developer/admin), with the role enforced at the proxy/API layer (app/src/proxy.ts gates /api/admin, /api/settings, /api/ingest, /api/audit-log for role=admin). Consuming the role in the UI was explicitly out of scope for that PR.

Problem

In identity mode, the Settings page still shows the shared-password admin prompt. AdminGate (app/src/components/auth/admin-gate.tsx) calls GET /api/auth/verify-admin, which returns required based solely on whether ADMIN_PASSWORD is set — it has no awareness of the identity role. So an identity admin is still prompted for the admin password, which is redundant (the proxy already enforces role=admin on the underlying /api/settings/* calls).

Proposed follow-up

  1. Identity-aware admin gate — in identity mode, an identity admin (role=admin) skips the password prompt; a developer is denied (no password fallback). Suggested touch points: app/src/app/api/auth/verify-admin/route.ts (consider the identity session + resolveRole) and app/src/components/auth/admin-gate.tsx.
  2. Nav gating — hide/disable the Settings nav entry for non-admin identity users.
  3. (Related, broader) Per-user data scoping and a "My Usage" page — noted as out of scope in Identity foundation: GitHub OAuth sign-in + developer/admin role in session #8; may warrant its own issue.

Keep changes additive so open/shared-password modes are unaffected.

Refs: #8

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions