Repository navigation
Conversation
…ments Talent Managers can open non-internal projects without membership, but READ_PROJECT_MEMBER, READ_PROJECT_INVITE_NOT_OWN, and VIEW_PROJECT_ATTACHMENT only granted non-members access through manager-tier roles. GET /projects/:id therefore stripped members and invites (Work "Users" tab showed no members) and GET /projects/:id/attachments returned 403 (Assets Library showed "Insufficient permissions"). Grant the Talent Manager roles these three read permissions. Internal-project membership is still enforced by ProjectContextInterceptor and getProject, and member, invite, and attachment mutations keep their project-role checks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related JIRA Ticket
PM-6515
What's in this PR?
QA follow-up (comment). After platform-ui#2428, Talent Managers can open non-internal projects without membership. Two workspace tabs still failed:
GET /v6/projects/:idstripsmemberswhen the caller lacksREAD_PROJECT_MEMBER, and strips other users' invites withoutREAD_PROJECT_INVITE_NOT_OWN.GET /v6/projects/:id/attachmentsrequiresVIEW_PROJECT_ATTACHMENT.All three permissions only let non-members through via manager-tier roles (
hasManagerTopcoderRole), and that list doesn't include the Talent Manager roles. This PR addsTalent ManagerandTopcoder Talent Managerto these three read permissions only.Unchanged:
ProjectContextInterceptorrejects them on nested/projects/:projectId/*routes, andProjectService.getProjectrejects them on the project read.Swagger permission summaries (
permission-docs.utils.ts),docs/PERMISSIONS.mdand the README's Talent Manager section are updated to match.This change alone makes both tabs load. Companion UI PR platform-ui#2432 hides the Assets Library's Add New File / Add New Link button for non-members, since the API still rejects their attachment creates.
Validation
PermissionService: Talent Manager roles get the three read permissions without membership, every related mutation stays denied, andTopcoder Userstill needs membership.ProjectService.getProjectwith the realPermissionService: a non-member Talent Manager gets members, invites and attachments back.jeston project, project-member, project-invite, project-attachment, shared services, interceptors and utils: 322 passed, 3 skipped.jestrun: the same 11 suites / 15 tests fail on cleanorigin/dev(metadata services andjwt.service), so those failures pre-date this change.eslint: clean.nest build: passes.Manual QA
🤖 Generated with Claude Code