trackslash
TRACK-84 P2

Show your permissions for the project in a box above Access on the About page

0
All issues

Description

Problem

The About page never says what the current viewer is allowed to do in the project. Edit controls simply appear or don't:

  • The Access settings button needs CanManageMembers.
  • The project image picker needs CanWrite.
  • Other sections are gated the same way.

A read-only member, a signed-in non-member of a public project, or a signed-out visitor sees a page with fewer controls and no explanation. They can't tell whether they lack permission or whether the feature doesn't exist.

Expected behavior

Add a new section at the top of the About page aside, above Access, e.g. titled "Your access". It shows:

  • Your role, as a badge in the same style as the Access badges (TRACK-83). Roles: Owner, Member, Read-only, Not a member, or Signed out.
  • A short list of what you can and can't do in this project, each item with a check or lock icon:
    • View the project and its issues
    • Create issues
    • Edit issues and project details
    • Manage access and settings
    • Delete the project
  • Where it helps, a hint about how to get more access. For example, a signed-out visitor to a project with public issue creation sees "Sign in to create issues".

Acceptance criteria

  • The box is built from the same permission checks the server enforces: the existing uiProjectPanelData flags (Anonymous, CanWrite, CanCreateIssues, CanManageMembers, CanDeleteProject) and the member role (model.ProjectMemberRole: member / readonly). It must never claim a permission the server would reject, or hide one it would allow.
  • Each viewer type gets the correct role and permission list:
    • owner
    • member
    • read-only member
    • signed-in non-member of a public project, with public issue creation on and off
    • signed-out visitor to a public project
  • Icons are aria-hidden, and each item's allowed/denied state is conveyed in text for screen readers.
  • Works on mobile and in light and dark modes.
  • Tests cover every viewer type listed above.

Notes

The alternative considered was a padlock in the top-right corner of each section the viewer can't edit, with a hover tooltip explaining their permissions. A single summary box above Access was preferred.

Related

TRACK-83 restyles the Access section directly below this box.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/track-slash-app/pull/177 (merged as 9127840).

A new "Your access" card sits above Access on the About page.

  • Role: an access badge with a one-line summary.
    • Tinted: Owner, Site admin, Member.
    • Neutral: Read-only, Not a member, Signed out.
  • Permissions: five rows (view, create issues, edit, manage access and settings, delete the project), each with a check or lock icon and screen-reader "Allowed:" / "Not allowed:" text.
  • Hint:
    • Signed-out visitors get a "Sign in" link: "to create issues" when public issue creation is on, "if you are a member of this project" otherwise.
    • Read-only members and non-members are pointed at the owner.
    • Members are told only the owner can manage access or delete the project.

uiProjectViewerAccessFor builds the card from the same store.ProjectPermissions the handlers enforce, and the integration test cross-checks every row against ProjectPermissionsForUser for all eight viewer types. Site admins who aren't the owner show as "Site admin", since they have owner-level rights.