Skip to content

feat(core): add generic permission map resolver with core utils and types gating infra - #418

Open
grandmaester wants to merge 11 commits into
feat/my-org-ea-branchfrom
feat/permission-gating-infrastructure
Open

feat(core): add generic permission map resolver with core utils and types gating infra#418
grandmaester wants to merge 11 commits into
feat/my-org-ea-branchfrom
feat/permission-gating-infrastructure

Conversation

@grandmaester

@grandmaester grandmaester commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Summary

Foundation for permission-based UI gating: a generic, module-agnostic permission resolver plus the Member Management permission declarations that build on it.

This is PR 1 of 2 for the permission infrastructure. Follow-up: (2) PermissionProvider context, usePermissions hook and PermissionDeniedTooltip.

Why

Components currently gate mutations with a coarse binary readOnly prop. The MyOrganization API exposes granular per-resource permissions, so we're moving to fine-grained checks.

Two design goals shaped this revision:

  1. Module-agnostic. Gating is not a My Organization concern — My Account and MFA step-up will need the same machinery, so the permissions module moved out from under my-organization/ to services/permissions/.
  2. No repeated logic per module. Onboarding a new module should be a declaration, not another copy of the same hasPermission + readOnly wiring. Each module contributes a data-only permission map and touches no shared code.

What

packages/core

services/permissions/ (moved up from services/my-organization/permissions/)

  • permission-map.tscreatePermissionResolver(spec) builds a resolver that turns granted scopes into named boolean flags. An array rule requires every scope; { any: [...] } requires at least one. readOnly (suppresses everything) and allowAll (used when no permission source is mounted) are applied centrally, so no call site repeats them. Return type is inferred from the spec, so a typo in a flag name is a compile error.
  • permission-utils.tshasPermission, hasAnyPermission, hasAllPermissions (unchanged).
  • permission-types.ts — trimmed to just OauthScope, the SDK-sourced union that keeps every scope string type-checked.
export const getMemberManagementPermissions = createPermissionResolver({
  canInvite: ['create:my_org:member_invitations'],
  canAssignRole: ['create:my_org:member_roles'],
  canRemoveRole: ['delete:my_org:member_roles'],
  canRemoveFromOrganization: ['delete:my_org:memberships'],
  canRevokeInvitation: ['delete:my_org:member_invitations'],
  // Resend revokes then recreates, so it needs both scopes.
  canResendInvitation: ['delete:my_org:member_invitations', 'create:my_org:member_invitations'],
  canShowMemberMenu: { any: ['create:my_org:member_roles', 'delete:my_org:memberships'] },
  canShowInvitationMenu: { any: ['delete:my_org:member_invitations'] },
} as const);

Packages

  • packages/core
  • packages/react
  • examples

Testing

image
  • This change adds unit test coverage
  • Tested for both SPA and RWA flows, all example apps working
  • All existing and new tests complete without errors

Checklist

  • Breaking change
  • Requires docs update
  • Backward compatible

Contributing

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 070f0240-2294-4281-80c8-ac4c1d0b9023

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Adds MyOrganization permission manifests, query keys, API types, public exports, and React utilities for permission checks and tier calculation. Core now consumes the packaged SDK tarball locally, and the utilities include Vitest coverage.

Changes

MyOrganization permissions

Layer / File(s) Summary
Permission contracts and exports
packages/core/src/services/my-organization/permissions/*, packages/core/src/services/my-organization/index.ts
Defines the permission manifest, derived permission type, query keys, API aliases, permission tiers, and barrel exports.
Permission evaluation utilities
packages/react/src/lib/utils/my-organization/permission-utils.ts, packages/react/src/lib/utils/my-organization/__tests__/*
Adds permission presence checks and resource-based tier calculation with Vitest coverage.
Local SDK package wiring
auth0-myorganization-js-1.1.0.tgz, packages/core/package.json
Adds the SDK tarball and changes the core dependency to a local file reference.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately identifies the permission-based infrastructure, core utilities, and types added by the pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/permission-gating-infrastructure

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@grandmaester grandmaester changed the title feat(permissions): add permission manifest, types, and utilities [PR 1/3] feat(core, react): add permission manifest, types, and utilities Jul 22, 2026
@grandmaester grandmaester self-assigned this Jul 22, 2026
@grandmaester grandmaester added the enhancement New feature or request label Jul 22, 2026
@grandmaester

Copy link
Copy Markdown
Contributor Author

@coderabbitai Review the PR changes

Comment thread packages/core/src/services/my-organization/index.ts Outdated
Comment thread packages/core/src/services/my-organization/permissions/permission-manifest.ts Outdated
Comment thread packages/react/src/lib/utils/my-organization/permission-utils.ts Outdated
@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

@grandmaester I’ll review the PR changes, including the permission manifest, SDK integration, public exports, and permission utility edge cases.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/core/package.json`:
- Line 55: Update the `@auth0/myorganization-js` dependency in packages/core so
the published package does not reference the repository-relative file: archive;
use the appropriate registry version or ensure packaging rewrites it to a
consumer-available dependency.

In `@packages/react/src/lib/utils/my-organization/permission-utils.ts`:
- Around line 65-73: Update getResourceVerbs to recognize only permissions with
exactly three segments matching <verb>:my_org:<resource>; require the namespace
segment to be my_org and reject trailing segments or other namespaces before
adding the verb.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 43807a54-afdf-4022-9646-d1e292e5f070

📥 Commits

Reviewing files that changed from the base of the PR and between 798a1f6 and d8094de.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • auth0-myorganization-js-1.1.0.tgz
  • packages/core/package.json
  • packages/core/src/services/my-organization/index.ts
  • packages/core/src/services/my-organization/permissions/index.ts
  • packages/core/src/services/my-organization/permissions/permission-manifest.ts
  • packages/core/src/services/my-organization/permissions/permission-query-keys.ts
  • packages/core/src/services/my-organization/permissions/permission-types.ts
  • packages/react/src/lib/utils/my-organization/__tests__/permission-utils.test.ts
  • packages/react/src/lib/utils/my-organization/permission-utils.ts

Comment thread packages/core/package.json
Comment thread packages/core/src/services/my-organization/permissions/permission-utils.ts Outdated
Comment thread packages/core/src/services/my-organization/permissions/index.ts Outdated
Comment thread packages/core/src/services/my-organization/permissions/permission-manifest.ts Outdated
Comment thread packages/core/src/services/my-organization/permissions/permission-manifest.ts Outdated
Comment thread packages/core/src/services/my-organization/permissions/permission-utils.ts Outdated
@grandmaester grandmaester changed the title feat(core, react): add permission manifest, types, and utilities feat(permissions): add permission manifest, types, and utilities Jul 22, 2026
@grandmaester grandmaester changed the title feat(permissions): add permission manifest, types, and utilities feat(permissions): add permission manifest constant, types utilities, my-org tarball Jul 22, 2026
Comment thread packages/core/src/services/my-organization/permissions/permission-utils.ts Outdated
@grandmaester grandmaester changed the title feat(permissions): add permission manifest constant, types utilities, my-org tarball refactor(permissions): add generic permission resolver, move permissions module Aug 12, 2026
grandmaester added a commit that referenced this pull request Aug 12, 2026
Aligns the runtime permission layer with the resolver from PR #418. The
granted permissions will come from an ID token claim, so the provider no
longer fetches them from `GET /my-org/user-permissions`.

- `PermissionProvider` now takes the granted `permissions` as a prop instead
  of running a manifest-driven query. The token-claim read is marked TODO
  pending SDK support.
- `usePermissions` returns `{ permissions, createPermissionResolver }`. A
  module passes its permission map and gets named boolean flags back, so
  components never handle scope strings themselves.
- Outside a provider the resolver is called with `allowAll`, preserving the
  previous admin-fallback behaviour for consumers that never mount it.
- Drop `isLoading`, `hasProvider`, `refetch` and `getUserTier` from the hook —
  there is no query to await or refetch, and tiering is now per action.
- Move permission types out of `types/my-organization/` to `types/permissions/`
  to match the core layout.
- Fix `PermissionDeniedTooltip` reading `errors.forbidden`; the key is
  `common.error.forbidden`, so the raw key string was being rendered.
- Remove the now-unused `PERMISSION_STALE_TIME_MS` constant and the
  `configuration.members.get` core-client mock.
- Add admin/editor/viewer permission fixtures for tests and local development.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@grandmaester grandmaester changed the title refactor(permissions): add generic permission resolver, move permissions module refactor(permissions): add generic permission map resolver with core utils and types gating infra Aug 12, 2026
@grandmaester grandmaester changed the title refactor(permissions): add generic permission map resolver with core utils and types gating infra feat(core, react): add generic permission map resolver with core utils and types gating infra Aug 14, 2026
@grandmaester grandmaester changed the title feat(core, react): add generic permission map resolver with core utils and types gating infra feat(core): add generic permission map resolver with core utils and types gating infra Aug 14, 2026
Comment thread packages/core/src/services/permissions/permission-utils.ts Outdated
Comment thread packages/core/src/services/permissions/permission-map.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants