Jobs: the restricted sheets, derived from the permission matrix #178

Closed
opened 2026-08-23 19:46:06 +00:00 by nalum · 0 comments
Owner

Part of the jobs flow redesign. The design handoff (design_handoff_jobs_flow, held outside the repo) is the source; the facts it depends on are repeated here so this issue stands alone.

Fewer permissions means fewer rows, never disabled ones. Which rows a reader gets comes from the per-verb matrix, not from a role bucket. Admin and Member manage any job (svc/authz.go:38), so both always get the full sheet. A child gets one of two shapes.

A child who owns the job — the common case. Who and Worth are shown without a chevron (a child cannot AssignUser to another person, and cannot LinkItem). The ... button is absent altogether: Delete and SetRepeat are both barred, which would leave a one-item menu. Remove it on a sub-job is absent for the same reason (permissions.go:99). Everything else works, including the tick — they own it.

A child on someone else's job is the genuinely read-only case: CompleteItem requires the owner, so the footer must not promise a tick. Who is shown without a chevron — whose job it is, is this reader's first question. Sub-jobs are listed with inert checkboxes drawn as read marks, except one they own themselves, which is tickable and is the only live control on the sheet. No footer otherwise; never a dead Done.

An unowned job is the exception in both shapes: the server leaves it open to anyone, so the Who row and the tick come back to life.


Two requirements added after #213 shipped

The job sheet went out to the family's cluster three times before it was right.
Seven visual defects, none caught by a suite: pickers that unfolded forms
instead of opening, three Save buttons on a commit-on-blur screen, (optional)
labels, a reward's name used as a field label, an unstyled add row, checkboxes
with a ghosted tick, and a create form with a browser spinner. Every one had to
be found by a person looking at a screen.

1. Screenshot goldens are part of this ticket

Record gallery (Playwright) and Roborazzi cases for every surface this ticket
builds or visibly changes, and treat them as a deliverable rather than a
follow-up. Three of #213's defects — the unstyled add row, the ghosted
checkboxes, the spinner in the create form — were pixel faults that a golden
would have caught before a deploy did.

#172 deferred its goldens on the reasoning that later tickets would re-record
them. That reasoning was sound then and is not now: the row grammar and the
pickers are settled, so an image recorded here stays valid.

Mechanics, from AGENTS.md: a new case rides in the same commit as the code
that adds it — a commit that adds a gallery or Roborazzi case without its image
is red on its own, because check / web runs npm run test:screens and
android / build runs verifyRoborazziDebug. A re-recorded existing case
goes in its own commit, so the reviewable diff stays code.

2. Check for leaked form styling before you finish

Every visual defect on #213 came from one place: the shipped app's form
fragments reused inside the new row grammar. They pass every test, because the
tests assert the pieces exist rather than that the screen reads right.

Before you call this done, grep the surfaces you touched and report what you
found and what you did about each:

  • a raw <input> / OutlinedTextField / BasicTextField outside the row and
    picker components — a form field dropped into a list of rows
  • type="number", which renders browser spinner arrows
  • btn, link-btn, btn-quiet or TextButton where a row or a quiet row
    verb belongs — underlined links reading as broken text
  • (optional) in any label — §8 names that pattern as the form admitting it
    should not have asked
  • any Save button on a surface that commits on blur, including Save changes and Save the points
  • a disabled-and-grey control where law 5 wants it absent
  • a record's title used as a field row's label — that column is for a
    field's name (Who, When, Worth), and a long title wraps in it

If your ticket is the first to land after this was written, add the check to
AGENTS.md beside the goldens rule, so it stops being a thing I remember to say.

Part of the jobs flow redesign. The design handoff (`design_handoff_jobs_flow`, held outside the repo) is the source; the facts it depends on are repeated here so this issue stands alone. Fewer permissions means fewer rows, never disabled ones. Which rows a reader gets comes from the per-verb matrix, not from a role bucket. Admin and Member manage any job (`svc/authz.go:38`), so both always get the full sheet. A child gets one of two shapes. **A child who owns the job** — the common case. Who and Worth are shown without a chevron (a child cannot `AssignUser` to another person, and cannot `LinkItem`). The `...` button is absent altogether: Delete and `SetRepeat` are both barred, which would leave a one-item menu. `Remove it` on a sub-job is absent for the same reason (`permissions.go:99`). Everything else works, including the tick — they own it. **A child on someone else's job** is the genuinely read-only case: `CompleteItem` requires the owner, so the footer must not promise a tick. Who is shown without a chevron — whose job it is, is this reader's first question. Sub-jobs are listed with inert checkboxes drawn as read marks, except one they own themselves, which is tickable and is the only live control on the sheet. No footer otherwise; never a dead `Done`. An unowned job is the exception in both shapes: the server leaves it open to anyone, so the Who row and the tick come back to life. --- ## Two requirements added after #213 shipped The job sheet went out to the family's cluster three times before it was right. Seven visual defects, none caught by a suite: pickers that unfolded forms instead of opening, three Save buttons on a commit-on-blur screen, `(optional)` labels, a reward's name used as a field label, an unstyled add row, checkboxes with a ghosted tick, and a create form with a browser spinner. Every one had to be found by a person looking at a screen. ### 1. Screenshot goldens are part of this ticket Record gallery (Playwright) and Roborazzi cases for every surface this ticket builds or visibly changes, and treat them as a deliverable rather than a follow-up. Three of #213's defects — the unstyled add row, the ghosted checkboxes, the spinner in the create form — were pixel faults that a golden would have caught before a deploy did. `#172` deferred its goldens on the reasoning that later tickets would re-record them. That reasoning was sound then and is not now: the row grammar and the pickers are settled, so an image recorded here stays valid. Mechanics, from AGENTS.md: a **new** case rides in the same commit as the code that adds it — a commit that adds a gallery or Roborazzi case without its image is red on its own, because `check / web` runs `npm run test:screens` and `android / build` runs `verifyRoborazziDebug`. A **re-recorded existing** case goes in its own commit, so the reviewable diff stays code. ### 2. Check for leaked form styling before you finish Every visual defect on #213 came from one place: the shipped app's form fragments reused inside the new row grammar. They pass every test, because the tests assert the pieces exist rather than that the screen reads right. Before you call this done, grep the surfaces you touched and report what you found and what you did about each: - a raw `<input>` / `OutlinedTextField` / `BasicTextField` outside the row and picker components — a form field dropped into a list of rows - `type="number"`, which renders browser spinner arrows - `btn`, `link-btn`, `btn-quiet` or `TextButton` where a row or a quiet row verb belongs — underlined links reading as broken text - `(optional)` in any label — §8 names that pattern as the form admitting it should not have asked - **any Save button on a surface that commits on blur**, including `Save changes` and `Save the points` - a disabled-and-grey control where law 5 wants it absent - a record's title used as a field row's `label` — that column is for a field's name (`Who`, `When`, `Worth`), and a long title wraps in it If your ticket is the first to land after this was written, add the check to AGENTS.md beside the goldens rule, so it stops being a thing I remember to say.
nalum closed this issue 2026-08-26 18:35:23 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#178
No description provided.