Repository navigation
feat(core): dynamic menu providers and runtime permission sources (#340, #334) - #407
Conversation
MenuRegistry.add_provider / remove; PermissionRegistry.add_source / invalidate_source, surfaced in all_permissions, groups and the role editor. Claude-Session: https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Deploying simple-module-python with
|
| Latest commit: |
dcb9841
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://34f8f921.simple-module-python.pages.dev |
| Branch Preview URL: | https://feat-340-334-runtime-menus-a.simple-module-python.pages.dev |
Materialise provider output before extending, show source labels in the user grants editor and role search, keep stored grants of currently unregistered source keys when saving a role or user. Claude-Session: https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4
…mory grants Anti-spoofing for runtime permission-source labels: the key is always rendered, the label is plain, trimmed, capped text, and switches are named with the key. Role saves also keep currently-unregistered stored grants in the in-memory map. Claude-Session: https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4
/ship resultsConverged in 1 round. Pushed 4 commits on top of d288750 (head a5a2008). Full report: https://claude.ai/artifact/EbEz5aCD65dHQ9kasdw3YZ Optimize: two safe edits (hoisted label lookup, restored a why-comment). Code review (3 passes, ends clean) fixed:
Accepted: a source that raises at boot is cached empty until QA (temporary fixture, not committed: 5 per-request menu items, a provider failing midway, a source with a misleading label, a raising source; browser agent plus API agent):
CI (local): |
# Conflicts: # modules/permissions/permissions/service.py
Fixes #340
Fixes #334
Design
Menu providers (#340).
MenuRegistry.add_provider(fn)takesfn(request)returning an iterable ofMenuItem; sync or async.InertiaLayoutDataMiddlewarenow calls the new asyncget_for_request, which collects provider items per request (after auth andrequest.state.tenant_idare resolved) and passes them to the unchangedget_for_userasextra_items, so role/permission filtering, translation, ordering and grouping are shared with static items. The static sorted cache is untouched. A provider that raises is logged and contributes nothing.MenuRegistry.remove(predicate)drops static items and invalidates the cache.Permission sources (#334).
PermissionRegistry.add_source(name, provider)with a sync provider returning keys or(key, label)pairs; output is cached per source and refreshed byinvalidate_source(name).all_permissions,groups,hasand thereforerole_mapwildcard expansion, admin's implicit all-permissions, the role editor and bothRequiresPermissionvariants see source permissions, with no changes needed outside the registry. Source permissions are persisted like any key. A failing source is logged and contributes nothing. The role editor API gains an additivePermissionGroupOut.labels.Additive only, to limit conflicts with #398 / #404.
Not done: label translation keys for source permissions (labels are literal;
t()needs literal keys in TSX), and no frontend rendering oflabelsyet.https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4