Description
Goal
Render every project page according to the current viewer's effective permissions so read-only viewers do not see actions they cannot use.
Acceptance criteria
- Project, issue, sprint, context, attachment, member, and settings views hide edit, create, delete, reorder, upload, and other mutation controls when the viewer lacks write access on that page.
- Permission checks use the same effective-access rules as the server-side mutation routes, including public read-only and read-only member access.
- Navigation and read-only interactions remain available.
- Empty states do not invite read-only viewers to create content.
- Mutation routes continue to enforce authorization independently of the UI.
- Shared templates/components receive a consistent capability signal rather than duplicating ad hoc role checks.
- Add render tests for owner, writable member, read-only member, and public viewer states on affected pages.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.