trackslash
TRACK-19 P2

Hide edit controls wherever the viewer lacks write access

0
All issues

Description

Goal

Render every project page according to the current viewer's effective permissions so read-only viewers do not see actions they cannot use.

Acceptance criteria

  • Project, issue, sprint, context, attachment, member, and settings views hide edit, create, delete, reorder, upload, and other mutation controls when the viewer lacks write access on that page.
  • Permission checks use the same effective-access rules as the server-side mutation routes, including public read-only and read-only member access.
  • Navigation and read-only interactions remain available.
  • Empty states do not invite read-only viewers to create content.
  • Mutation routes continue to enforce authorization independently of the UI.
  • Shared templates/components receive a consistent capability signal rather than duplicating ad hoc role checks.
  • Add render tests for owner, writable member, read-only member, and public viewer states on affected pages.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.