[christmas] Hide "Manage" nav link from viewers and tighten API allowlist to exact names - #390
Merged
Conversation
Owner
Author
This stack of pull requests is managed by Graphite. Learn more about stacking. |
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Hide the "Manage" nav link from viewers and show a friendly gate on the admin page
Previously, anyone signed in with the family (viewer) password could see the "Manage" link in the navbar and click through to a page full of permission errors. This tightens that up in two places:
Managerrole, fetched viamy_roleon shell load.ManageBody); viewers see a friendly message explaining they need the manager password, with a direct link to sign in as manager.The server-side middleware remains the true enforcement boundary — this is purely a UX improvement so viewers aren't greeted with a wall of errors.
Auth allowlist fix
The previous viewer endpoint check used
starts_with("list_"), which inadvertently granted viewers access tolist_participants,list_relationships,list_memberships,list_excluded_letters, andlist_all_excluded_letters— data that should only be visible to managers. The allowlist is now an explicit set of named endpoints matched after stripping the Dioxus-appended numeric hash suffix, so only the intended six endpoints are viewer-accessible. New tests cover exact-name matching, hash stripping, and the specific case wherelist_exchangesandlist_excluded_lettersshare a long common prefix.