Repository navigation
Conversation
|
Thanks for the pull request, @BryanttV! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
e19eacd to
3d1fd3b
Compare
3d1fd3b to
5453f7a
Compare
71a6623 to
447e245
Compare
fd932d0 to
768b626
Compare
Implement ADR 0028: GET /api/authz/v1/roles/ is queried by scope_type and returns paginated roles with the categories and permissions catalogs read from the authz schema models, with per-scope-type authorization and user_count calculated by scope type. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Update the roles endpoint to the revised ADR 0028: GET /api/authz/v1/roles/ is queried by a comma-separated scope_types list. Permissions and roles are the union across the requested scope types, the user must hold the view-team permission of each one, and user_count counts distinct users across them. Roles without a stored definition are not listed. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Each permission listed by GET /api/authz/v1/roles/ now exposes its scopes, the scope namespaces where it can be granted. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Replace the scope_types field of the response with scopes, using the backend namespaces (course-v1, lib), as defined in ADR 0028. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… catalog Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
447e245 to
d29c9a8
Compare
The changelog is no longer maintained by hand since the move to python-semantic-release. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Match the field name used by the authz schema. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Description
Implements ADR 0028.
GET /api/authz/v1/roles/is now queried by scope types (courseand/orlibrary) instead of a concrete scope. It returns the paginated roles together with the fullcategoriesandpermissionscatalogs, so the Admin Console can build its roles and permissions matrix from a single request.The catalog is read from the authz schema models (the same data the Casbin policy is rendered from), not from the Casbin policy itself.
Warning
Breaking Change
scope=lib:OpenedX:CSPROBscope_types=course,scope_types=libraryor a comma-separated list (scope_types=course,library)user_countmanage_library_team/ view permission on the given scopecourses.view_course_team(course) and/orcontent_libraries.view_library_team(library), held in any scope. The user needs the permission of each requested scope type{role, permissions, user_count}scopes,categories,permissionsandresultsChanges
API layer (
openedx_authz/api)catalog.pywithget_permission_catalog,get_category_catalogandget_role_catalog. They use a constant number of queries and read only from the schema models.scopes.get_user_counts_per_role_in_namespaces, which counts distinct users per role across all scopes of the given namespaces. A user assigned to a role in several namespaces is counted once.DefinitionKindenum (static/user_defined). Onlystaticis used today;user_definedis reserved for later.REST API (
openedx_authz/rest_api)ScopeTypePermission: a new permission class that maps eachscope_typeto the permission it needs.scope_typesis not rejected here. The view serializer answers400.ListRolesWithScopeSerializerandListRolesWithSeplaced byListRolesQuerySerializerand theRoleCatalog*`serializers.RoleListView: now uses the new permission class and serialization documented separately from401.data.py: addsSCOPE_TYPE_NAMESPACES(course→course-v1,library→lib).Example
{ "count": 4, "next": null, "previous": null, "scopes": [ "course-v1" ], "categories": [ { "id": "course_team_group", "display_name": "Course team & groups", "description": "Permissions for viewing and managing the course team, learner groups, and group configurations.", "icon": "Group" } ], "permissions": [ { "id": "courses.view_course_team", "namespace": "courses", "name": "view_course_team", "display_name": "View course team", "description": "See the list of users with a role assigned to this course.", "icon": "RemoveRedEye", "category_id": "course_team_group", "scopes": [ "course-v1" ] } ], "results": [ { "role": "course_admin", "display_name": "Course Admin", "description": "Can manage the course team and all course settings.", "icon": null, "definition_kind": "static", "permissions": [ "courses.view_course_team" ], "user_count": 5 } ] }categoriesandpermissionsare complete on every page. Only results are paginated.Testing Instructions
tutor dev run lms ./manage.py lms load_authz_schema. If the tables don't exist, apply migrations first. The new migration is0011_authz_schema_definitions:tutor dev run lms ./manage.py lms migrate openedx_authzadmin(superuser) and openhttp://local.openedx.io:8000/api/authz/v1/roles/?scope_types=coursein the browser. Expect a200response withscope_types,categories,permissions, and a paginatedresultslist of roles.?scope_types=library,?scope_types=course,libraryand?scope_types=course&page=1&page_size=1. The roles are paginated, butcategoriesandpermissionsstay complete on every page.scope_types, or the oldscopeparam, returns400.http://local.openedx.io:8000/api/authz/v1/roles/?scope_types=course. Expect a403response. Repeat with?scope_types=libraryand expect403as well.Merge checklist
Check off if complete or not applicable: