trackslash
TRACK-92 P2

Help-desk access mode: reporters file issues and see only their own

0
Sub-issue of TRACK-89 P2 Let private projects take issues from anyone signed in, like a help desk

Description

Third step of TRACK-89. It makes the helpdesk access mode selectable and implements the reporter experience described in TRACK-89:

  • a new-issue form that needs an account and ends with the trackslash footer line;
  • a "your issues" list;
  • the reporter's view of each of their issues, showing title, description, status, times, shared comments and their replies;
  • replies.

This works through the UI, REST and MCP.

A reporter gets no project-level read access. Every existing project route keeps refusing them, and only the reporter paths are opened:

  • create an issue;
  • list their own issues;
  • get their own issue, with the hidden fields removed;
  • list the shared comments on it and reply.

Someone else's issue returns the same not-found as a missing one. Help-desk projects never appear in a non-member's project listings. Refs in shared text are not expanded for reporters. Realtime and push notifications carry nothing beyond their own issues.

A blocked user gets a 403 on every route in the project, including their earlier issues.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/track-slash-app/pull/183 (merged as 41e287a).

  • The mode: helpdesk is a selectable access mode. Help-desk reporters get no project-level read, so every existing route keeps refusing them. Only these paths open, over the UI, REST and MCP:
    • filing with a title and description only;
    • listing their own issues;
    • reading their own issue as a ReporterIssue (title, description, open/in progress/closed status, times);
    • its shared comments, plus replies that are always shared.
  • Issue routes: every route that names an issue goes through issueRouteAccess. A blocked user gets a 403 everywhere, their own issues included. Another reporter's issue answers exactly like a missing one, and batch reads skip those issues.
  • Nothing else leaks: help desks never appear in a non-member's listings. Reporters get no realtime topics. Push notifications reach them only about their own issue, never its due date.
  • UI: reporters get the help-desk form, which ends with the quiet trackslash promo line, plus "Your issues" and a conversation page. Members get the Help desk option, the help-desk link on About and "Shared with the reporter".

Judgement calls:

  • Reporters get no realtime subscriptions at all, rather than filtered ones. The UI only uses realtime on the changelog page, so reporters lose nothing.
  • The reporter conversation reads oldest-first, ending at the reply box. Members' issue pages stay newest-first.
  • Priority, due date or an assignee sent by a reporter are rejected over REST and MCP, and silently ignored from the UI forms.