Child role: backend rights for list/meal management + expose the permission matrix #56
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#56
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Give the child role the backend rights to create and run the family's shared lists and meals, and expose the permission matrix so clients can gate affordances against it. The UI affordance work — making the clients actually show a child those controls — is split out to #61.
Scope (backend only)
1. Child rights on ownerless containers (done — PR #67). Lists and meals have no owner field, so there is nothing to scope a child to. Admit CHILD to the full verb set of both services, the same rights a member holds:
ItemListService: Create, Update, Delete, UncheckAll.MealService: Create, Update, Delete, PushIngredients.Rewards stay member-and-up (a child claims, never grants). The meal rota board (
MealRotaService) is untouched. Recorded in ADR-0028, with an end-to-end integration test driving a real child token through the interceptor.2. Expose the matrix (done — PR #69). The clients gated affordances on a hand-written
canEditflag that drifts from the server's matrix.SystemService.GetPermissionMatrixnow returns the enforced matrix as reference data, so clients gate against the real thing.Split out to #61
The UI affordance migration — the permission store,
can(service, method), removingcanEdit, the Meals library-vs-rota split, and the canon-doc corrections — moved to #61, which now owns all UI-honors-the-matrix work (web and Android) and consumes #69.Known interim gap
Until #61 lands, the web still hides a child's new list and meal controls: the capability exists server-side and the matrix is exposed, but the clients have not been migrated to consume it. A child can create lists and meals through the API and any matrix-aware client, but not yet through the shipped web or Android UI.
Definition of done
GetPermissionMatrixexposes the enforced matrix (PR #69).make checkpasses.update child roleto Child role: allow list/meal creation and fix UI hiding permitted create actionsnalum referenced this issue2026-08-14 11:50:24 +00:00
nalum referenced this issue2026-08-14 14:22:56 +00:00
Child role: allow list/meal creation and fix UI hiding permitted create actionsto Child role: backend rights for list/meal management + expose the permission matrix