You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add an endpoint saying who a project's work may be assigned to (#373)
* Add an endpoint saying who a project's work may be assigned to
Nothing below super admin listed users, so a screen could only offer the
signed-in person to themselves. This returns the people the assignment save
accepts: on the team, active, not a service account.
An id and a display name, and nothing else. The admin team view carries an
email because an administrator auditing who can reach a team needs one; a
picker does not, and shipping it would make every project page somewhere
addresses can be collected from.
Addressed by project rather than by team, so a caller never needs a team id to
look work up by, and gated at developer to match the assignment it feeds.
The list and the write share one query. A shared condition was the first
shape, and the security review showed it compiles to a cross join when a
caller forgets to join memberships, returning every active person in the
deployment with no error and no warning. Returning the query carries the join
with it.
* Record the new route in the OpenAPI snapshot
The drift gate is a snapshot of the wire surface, so adding an endpoint has to
show as a reviewed line rather than as a passing test. One line added and
nothing else moved.
0 commit comments