feat(authz): let children run shared lists and meals #67

Merged
nalum merged 1 commit from feat/child-shared-containers into main 2026-08-14 16:55:50 +00:00
Owner

Backend half of #56: admit the child role to the two ownerless shared container services.

Lists and meals have no owner field — unlike jobs, there is nothing to scope a child to. Treating their manager verbs as adult-only was the wrong model, so this admits CHILD to the full verb set of both services, the same rights a member holds:

  • ItemListService: Create, Update, Delete, UncheckAll
  • MealService: Create, Update, Delete, PushIngredients

Rewards stay member-and-up (a child claims, never grants). The meal rota board is untouched. No schema change — enforcement stays at the interceptor role gate.

Decision recorded in ADR-0028. A new end-to-end integration test drives a real child token through the interceptor to create, edit and delete a list and a meal, with a negative guard proving the token is genuinely child-scoped (reward-create still denied).

Part of #56 (backend). The UI affordance migration (canEdit → matrix) that surfaces these rights in the clients is tracked separately in #61.

Verified: make check and the integration suite pass.

🤖 Generated with Claude Code

Backend half of #56: admit the child role to the two ownerless shared container services. Lists and meals have no owner field — unlike jobs, there is nothing to scope a child to. Treating their manager verbs as adult-only was the wrong model, so this admits CHILD to the full verb set of both services, the same rights a member holds: - `ItemListService`: Create, Update, Delete, UncheckAll - `MealService`: Create, Update, Delete, PushIngredients Rewards stay member-and-up (a child claims, never grants). The meal rota board is untouched. No schema change — enforcement stays at the interceptor role gate. Decision recorded in ADR-0028. A new end-to-end integration test drives a real child token through the interceptor to create, edit and delete a list and a meal, with a negative guard proving the token is genuinely child-scoped (reward-create still denied). Part of #56 (backend). The UI affordance migration (`canEdit` → matrix) that surfaces these rights in the clients is tracked separately in #61. Verified: `make check` and the integration suite pass. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(authz): let children run shared lists and meals
All checks were successful
check / commits (push) Successful in 5s
check / web (push) Successful in 1m29s
check / go (push) Successful in 1m47s
9ed50a914d
Lists and meals are ownerless shared containers — unlike items, there is
no owner to scope a child to. Treating their manager verbs as adult-only
was the wrong model: a child is a trusted member of the household for the
family's shared lists and meal library. Admit CHILD to the full
ItemListService and MealService verb set (create, rename, delete,
uncheck-all; create, edit, delete, push-ingredients), the same rights a
member already holds. Rewards stay member-and-up (a child claims, never
grants); the meal rota board is untouched here. ADR-0028.
nalum force-pushed feat/child-shared-containers from 9ed50a914d
All checks were successful
check / commits (push) Successful in 5s
check / web (push) Successful in 1m29s
check / go (push) Successful in 1m47s
to 403e2a6096
All checks were successful
check / commits (pull_request) Successful in 5s
check / web (pull_request) Successful in 1m29s
check / go (pull_request) Successful in 2m34s
check / report (pull_request) Successful in 4s
2026-08-14 14:16:14 +00:00
Compare

Test report

Suite Tests Result Skipped
Unit 1330 ✅ pass 1
Integration 83 ✅ pass —

Coverage: 27.7%

Updated by the check workflow · commit 53d78cb549

<!-- ci-test-report --> ## Test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit | 1330 | ✅ pass | 1 | | Integration | 83 | ✅ pass | — | **Coverage:** 27.7% <sub>Updated by the check workflow · commit 53d78cb5493a2234dc08b06cd3b11ea4d6c0bf9c</sub>
nalum force-pushed feat/child-shared-containers from 403e2a6096
All checks were successful
check / commits (pull_request) Successful in 5s
check / web (pull_request) Successful in 1m29s
check / go (pull_request) Successful in 2m34s
check / report (pull_request) Successful in 4s
to 53d78cb549
Some checks failed
check / commits (pull_request) Successful in 7s
android / build (pull_request) Successful in 6m34s
check / go (pull_request) Successful in 3m14s
check / web (pull_request) Successful in 1m29s
android / report (pull_request) Successful in 7s
check / report (pull_request) Successful in 3s
check / commits (push) Has been cancelled
check / go (push) Has been cancelled
check / report (push) Has been cancelled
check / web (push) Has been cancelled
tag / tag (push) Has been cancelled
2026-08-14 16:03:15 +00:00
Compare

Android test report

Suite Tests Result Skipped
Unit (debug) 31 ✅ pass 0

Updated by the android workflow · commit 53d78cb549

<!-- android-test-report --> ## Android test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit (debug) | 31 | ✅ pass | 0 | <sub>Updated by the android workflow · commit 53d78cb5493a2234dc08b06cd3b11ea4d6c0bf9c</sub>
nalum changed target branch from fix/android-nav-labels-one-line to main 2026-08-14 16:55:42 +00:00
nalum merged commit 53d78cb549 into main 2026-08-14 16:55:50 +00:00
nalum deleted branch feat/child-shared-containers 2026-08-14 16:55:50 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!67
No description provided.