feat: split read vs write authz checks for certificates - #39008
feat: split read vs write authz checks for certificates#39008wgu-taylor-payne wants to merge 1 commit into
Conversation
|
Thanks for the pull request, @wgu-taylor-payne! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
3215e24 to
cadf7c1
Compare
Use COURSES_VIEW_CERTIFICATES for GET access and COURSES_MANAGE_CERTIFICATES for write access. Add can_manage flag to the response so the frontend knows whether to render edit controls. Course Editors and Auditors can now view certificates in read-only mode. ENG45-714
cadf7c1 to
17f1123
Compare
Description
Updates the certificates REST API v1 endpoint to use
courses.view_certificatesfor GET access andcourses.manage_certificatesfor write access. Adds acan_manageflag to the API response so the frontend can conditionally render edit controls.Previously, the GET handler checked
COURSES_MANAGE_CERTIFICATESwithLegacyAuthoringPermission.WRITE, which blocked Course Editors and Auditors from viewing certificates entirely. Per the design in openedx/openedx-authz#283 and openedx/openedx-authz#329, users with view access should see the page in read-only mode.User roles impacted: Course Editor, Course Auditor — can now view (but not edit) certificates when authz is enabled.
Changes:
cms/djangoapps/contentstore/rest_api/v1/views/certificates.py: UseVIEW_CERTIFICATESfor access gate, addcan_managecheckcms/djangoapps/contentstore/rest_api/v1/serializers/certificates.py: Addcan_managefieldcan_manage=True), editor/auditor (can_manage=False), and unauthorized (403)Rollback: Gated behind
AUTHZ_COURSE_AUTHORING_FLAG— disabling the flag reverts to legacy behavior.Supporting information
courses.view_certificatesenforcement in openedx-platform openedx-authz#395courses.view_certificatespermission openedx-authz#329, Design: Course Editor & Course Auditor screen restrictions openedx-authz#283Testing instructions
AUTHZ_COURSE_AUTHORING_FLAGfor a coursecourse_editorroleGET /api/contentstore/v1/certificates/{course_id}→ 200 withcan_manage: falsecourse_staffrole → 200 withcan_manage: trueDeadline
None