feat(authz): let children run shared lists and meals #67
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!67
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/child-shared-containers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Backend half of #56: admit the child role to the two ownerless shared container services.
Lists and meals have no owner field — unlike jobs, there is nothing to scope a child to. Treating their manager verbs as adult-only was the wrong model, so this admits CHILD to the full verb set of both services, the same rights a member holds:
ItemListService: Create, Update, Delete, UncheckAllMealService: Create, Update, Delete, PushIngredientsRewards stay member-and-up (a child claims, never grants). The meal rota board is untouched. No schema change — enforcement stays at the interceptor role gate.
Decision recorded in ADR-0028. A new end-to-end integration test drives a real child token through the interceptor to create, edit and delete a list and a meal, with a negative guard proving the token is genuinely child-scoped (reward-create still denied).
Part of #56 (backend). The UI affordance migration (
canEdit→ matrix) that surfaces these rights in the clients is tracked separately in #61.Verified:
make checkand the integration suite pass.🤖 Generated with Claude Code
9ed50a914d403e2a6096Test report
Coverage: 27.7%
Updated by the check workflow · commit
53d78cb549403e2a609653d78cb549Android test report
Updated by the android workflow · commit
53d78cb549