feat(system): expose the permission matrix over RPC #69

Merged
nalum merged 1 commit from feat/permission-matrix-rpc into main 2026-08-14 16:55:56 +00:00
Owner

Second part of #56: give clients the real permission matrix to gate affordances against, instead of a hand-kept mirror.

The web derives create/manage affordances from a coarse canEdit = Admin||Member flag — a client-side guess that drifts from the server's PermissionMatrix. That drift is what hides create controls from a child even where the matrix permits them. Rather than replace one hand-mirror with a smaller one, this exposes the server's actual matrix.

Adds SystemService.GetPermissionMatrix, returning roles.PermissionMatrix verbatim — the same reference data the auth interceptor enforces. Readable by every signed-in role; the server stays authoritative, this is advisory reference data only. The handler is trivial (return the compiled-in matrix); the RPC is auto-served by the Connect handler.

The web and Android consumers that read this matrix (fetch once, checkPermission(service, method, roles), replace canEdit) are tracked in #61. The CLI can consume the same endpoint.

Verified: make check passes (buf format/lint, Go tests, web build). Generated Go and Android clients are committed; web/src/gen is build-time generated and gitignored.

Closes #56 (the backend half — child rights plus this RPC).

🤖 Generated with Claude Code

Second part of #56: give clients the real permission matrix to gate affordances against, instead of a hand-kept mirror. The web derives create/manage affordances from a coarse `canEdit = Admin||Member` flag — a client-side guess that drifts from the server's `PermissionMatrix`. That drift is what hides create controls from a child even where the matrix permits them. Rather than replace one hand-mirror with a smaller one, this exposes the server's actual matrix. Adds `SystemService.GetPermissionMatrix`, returning `roles.PermissionMatrix` verbatim — the same reference data the auth interceptor enforces. Readable by every signed-in role; the server stays authoritative, this is advisory reference data only. The handler is trivial (return the compiled-in matrix); the RPC is auto-served by the Connect handler. The web and Android consumers that read this matrix (fetch once, `checkPermission(service, method, roles)`, replace `canEdit`) are tracked in #61. The CLI can consume the same endpoint. Verified: `make check` passes (buf format/lint, Go tests, web build). Generated Go and Android clients are committed; `web/src/gen` is build-time generated and gitignored. Closes #56 (the backend half — child rights plus this RPC). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
feat(system): expose the permission matrix over RPC
All checks were successful
check / commits (pull_request) Successful in 5s
check / web (pull_request) Successful in 1m30s
check / go (pull_request) Successful in 2m32s
check / report (pull_request) Successful in 4s
55da86bbb9
The clients derive create and manage affordances by hand from roles,
which drifts from the server's real PermissionMatrix — the root of the
canEdit defect in #56. Add SystemService.GetPermissionMatrix so a client
reads the server's actual matrix and gates affordances against the same
source the interceptor enforces, instead of a hand-kept mirror. Reference
data, open to every signed-in role. Part of #56.

Test report

Suite Tests Result Skipped
Unit 1330 ✅ pass 1
Integration 83 ✅ pass —

Coverage: 27.7%

Updated by the check workflow · commit d45901838c

<!-- ci-test-report --> ## Test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit | 1330 | ✅ pass | 1 | | Integration | 83 | ✅ pass | — | **Coverage:** 27.7% <sub>Updated by the check workflow · commit d45901838c99bd8fff9a1a0552a311b1e0dd8330</sub>
nalum force-pushed feat/permission-matrix-rpc from 55da86bbb9
All checks were successful
check / commits (pull_request) Successful in 5s
check / web (pull_request) Successful in 1m30s
check / go (pull_request) Successful in 2m32s
check / report (pull_request) Successful in 4s
to d45901838c
Some checks failed
check / commits (pull_request) Successful in 5s
android / build (pull_request) Successful in 6m39s
check / web (pull_request) Successful in 1m45s
check / go (pull_request) Successful in 2m41s
android / report (pull_request) Successful in 3s
check / report (pull_request) Successful in 4s
check / commits (push) Has been cancelled
check / go (push) Has been cancelled
check / report (push) Has been cancelled
check / web (push) Has been cancelled
tag / tag (push) Has been cancelled
android / report (push) Has been cancelled
android / build (push) Has been cancelled
2026-08-14 16:03:15 +00:00
Compare

Android test report

Suite Tests Result Skipped
Unit (debug) 31 ✅ pass 0

Updated by the android workflow · commit d45901838c

<!-- android-test-report --> ## Android test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit (debug) | 31 | ✅ pass | 0 | <sub>Updated by the android workflow · commit d45901838c99bd8fff9a1a0552a311b1e0dd8330</sub>
nalum changed target branch from feat/child-shared-containers to main 2026-08-14 16:55:50 +00:00
nalum merged commit d45901838c into main 2026-08-14 16:55:56 +00:00
nalum deleted branch feat/permission-matrix-rpc 2026-08-14 16:55:56 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!69
No description provided.