Skip to content

PM-6515 Let Talent Managers read project members, invites, and attachments -> dev - #50

Merged
jmgasper merged 1 commit into
devfrom
PM-6515
Oct 5, 2026
Merged

jmgasper merged 1 commit into
devfrom
PM-6515

Conversation

@jmgasper

@jmgasper jmgasper commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Related JIRA Ticket

PM-6515

What's in this PR?

QA follow-up (comment). After platform-ui#2428, Talent Managers can open non-internal projects without membership. Two workspace tabs still failed:

  • Users showed "No project members yet". GET /v6/projects/:id strips members when the caller lacks READ_PROJECT_MEMBER, and strips other users' invites without READ_PROJECT_INVITE_NOT_OWN.
  • Assets Library showed "Insufficient permissions". GET /v6/projects/:id/attachments requires VIEW_PROJECT_ATTACHMENT.

All three permissions only let non-members through via manager-tier roles (hasManagerTopcoderRole), and that list doesn't include the Talent Manager roles. This PR adds Talent Manager and Topcoder Talent Manager to these three read permissions only.

Unchanged:

  • Internal projects still require active membership. ProjectContextInterceptor rejects them on nested /projects/:projectId/* routes, and ProjectService.getProject rejects them on the project read.
  • Member, invite and attachment create/update/delete permissions keep their existing project-role checks. Tests assert they stay denied for non-member Talent Managers.

Swagger permission summaries (permission-docs.utils.ts), docs/PERMISSIONS.md and the README's Talent Manager section are updated to match.

This change alone makes both tabs load. Companion UI PR platform-ui#2432 hides the Assets Library's Add New File / Add New Link button for non-members, since the API still rejects their attachment creates.

Validation

  • New tests:
    • PermissionService: Talent Manager roles get the three read permissions without membership, every related mutation stays denied, and Topcoder User still needs membership.
    • ProjectService.getProject with the real PermissionService: a non-member Talent Manager gets members, invites and attachments back.
    • All 4 Talent Manager cases fail on the old code and pass with this change.
  • jest on project, project-member, project-invite, project-attachment, shared services, interceptors and utils: 322 passed, 3 skipped.
  • Full jest run: the same 11 suites / 15 tests fail on clean origin/dev (metadata services and jwt.service), so those failures pre-date this change.
  • eslint: clean.
  • nest build: passes.

Manual QA

  1. Sign in as a Talent Manager who is not a member of a non-internal project (e.g. project 100591 on dev).
  2. Open Users: the project's members (and any pending invites) are listed, read-only, with no Add/Invite buttons.
  3. Open Assets Library: the project's links and files are listed. The add button is hidden once platform-ui#2432 is deployed.
  4. Open an internal project you are not an active member of: access is still denied.

🤖 Generated with Claude Code

…ments

Talent Managers can open non-internal projects without membership, but
READ_PROJECT_MEMBER, READ_PROJECT_INVITE_NOT_OWN, and VIEW_PROJECT_ATTACHMENT
only granted non-members access through manager-tier roles. GET /projects/:id
therefore stripped members and invites (Work "Users" tab showed no members)
and GET /projects/:id/attachments returned 403 (Assets Library showed
"Insufficient permissions").

Grant the Talent Manager roles these three read permissions. Internal-project
membership is still enforced by ProjectContextInterceptor and getProject, and
member, invite, and attachment mutations keep their project-role checks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jmgasper
jmgasper merged commit 73d2934 into dev Oct 5, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant