Jobs: the restricted sheets, derived from the permission matrix #178
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#178
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of the jobs flow redesign. The design handoff (
design_handoff_jobs_flow, held outside the repo) is the source; the facts it depends on are repeated here so this issue stands alone.Fewer permissions means fewer rows, never disabled ones. Which rows a reader gets comes from the per-verb matrix, not from a role bucket. Admin and Member manage any job (
svc/authz.go:38), so both always get the full sheet. A child gets one of two shapes.A child who owns the job — the common case. Who and Worth are shown without a chevron (a child cannot
AssignUserto another person, and cannotLinkItem). The...button is absent altogether: Delete andSetRepeatare both barred, which would leave a one-item menu.Remove iton a sub-job is absent for the same reason (permissions.go:99). Everything else works, including the tick — they own it.A child on someone else's job is the genuinely read-only case:
CompleteItemrequires the owner, so the footer must not promise a tick. Who is shown without a chevron — whose job it is, is this reader's first question. Sub-jobs are listed with inert checkboxes drawn as read marks, except one they own themselves, which is tickable and is the only live control on the sheet. No footer otherwise; never a deadDone.An unowned job is the exception in both shapes: the server leaves it open to anyone, so the Who row and the tick come back to life.
Two requirements added after #213 shipped
The job sheet went out to the family's cluster three times before it was right.
Seven visual defects, none caught by a suite: pickers that unfolded forms
instead of opening, three Save buttons on a commit-on-blur screen,
(optional)labels, a reward's name used as a field label, an unstyled add row, checkboxes
with a ghosted tick, and a create form with a browser spinner. Every one had to
be found by a person looking at a screen.
1. Screenshot goldens are part of this ticket
Record gallery (Playwright) and Roborazzi cases for every surface this ticket
builds or visibly changes, and treat them as a deliverable rather than a
follow-up. Three of #213's defects — the unstyled add row, the ghosted
checkboxes, the spinner in the create form — were pixel faults that a golden
would have caught before a deploy did.
#172deferred its goldens on the reasoning that later tickets would re-recordthem. That reasoning was sound then and is not now: the row grammar and the
pickers are settled, so an image recorded here stays valid.
Mechanics, from AGENTS.md: a new case rides in the same commit as the code
that adds it — a commit that adds a gallery or Roborazzi case without its image
is red on its own, because
check / webrunsnpm run test:screensandandroid / buildrunsverifyRoborazziDebug. A re-recorded existing casegoes in its own commit, so the reviewable diff stays code.
2. Check for leaked form styling before you finish
Every visual defect on #213 came from one place: the shipped app's form
fragments reused inside the new row grammar. They pass every test, because the
tests assert the pieces exist rather than that the screen reads right.
Before you call this done, grep the surfaces you touched and report what you
found and what you did about each:
<input>/OutlinedTextField/BasicTextFieldoutside the row andpicker components — a form field dropped into a list of rows
type="number", which renders browser spinner arrowsbtn,link-btn,btn-quietorTextButtonwhere a row or a quiet rowverb belongs — underlined links reading as broken text
(optional)in any label — §8 names that pattern as the form admitting itshould not have asked
Save changesandSave the pointslabel— that column is for afield's name (
Who,When,Worth), and a long title wraps in itIf your ticket is the first to land after this was written, add the check to
AGENTS.md beside the goldens rule, so it stops being a thing I remember to say.
nalum referenced this issue2026-08-24 13:07:09 +00:00