feat(settings): complete #802 settings API integration gaps - #808
Conversation
Seme30
left a comment
There was a problem hiding this comment.
Looks like the remaining #802 integration pass: permission-gated tabs, tag load errors, /settings rewrite removed, and tests for reads/writes/validation/forbidden. CI is green.
P2
-
frontend/app/settings/page.tsx:44-63stillPromise.alls every settings endpoint, including tabs the user cannot see. Users withoutManage Global Site Settings/ role-edit permissions will get a burst of 403s on every page load. Fetch only the panels the nav will show. -
frontend/app/settings/layout.tsx:78falls back todefaultTab = "roles"whennavItemsis empty, so a user with no settings permissions can still land on a hidden roles panel.
Not blocking merge for the #802 gaps this PR claims, but please fix the 403 fan-out if you touch the page again. This does not close #801 (/users/settings is still rewritten).
Share settings nav/access helpers between layout and page so SSR loads only endpoints for visible tabs. Users without role or site-settings permissions no longer trigger a 403 fan-out on page load, and users with no settings access see an empty state instead of defaulting to the hidden roles tab.
Summary
/settingslegacy rewrite so the Next.js page is canonicalTest Plan
pnpm run frontend:typecheckdotnet test SettingsApiController(4 tests)