Skip to content

Centralize resource authorization decisions - #126

Merged
wienans merged 3 commits into
mainfrom
t3code/improve-codebase-architecture
Jul 14, 2026
Merged

wienans merged 3 commits into
mainfrom
t3code/improve-codebase-architecture

Conversation

@wienans

@wienans wienans commented Jul 12, 2026

Copy link
Copy Markdown
Owner

Summary

  • add one resource authorization decision module for view, edit, delete, and named Access management
  • bind Exercise, TacticBoard, and PracticePlan Access lookups behind resource adapters
  • migrate individual-resource controller checks to consistent Owner, Admin, grant, and Public rules
  • keep edit authority for visibility and Share Link changes while restricting deletion and Access management to Owner/Admin
  • map unauthenticated and forbidden decisions consistently to 401 and 403

Tests

  • npm run build
  • authorization suites: 183 tests passed
  • full server suite: 26/27 suites passed; the remaining MongoMemoryServer startup timeout passed all 6 tests when rerun alone

Scope

  • collection visibility filtering remains unchanged and out of scope
  • Share Link token resolution remains separate from User authorization

@wienans
wienans merged commit be6094c into main Jul 14, 2026
1 check passed
@wienans
wienans deleted the t3code/improve-codebase-architecture branch July 14, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant