Skip to content

feat(settings): complete #802 settings API integration gaps - #808

Merged
christopherpickering merged 2 commits into
devfrom
feat/issue-802-settings-api-integration
Sep 25, 2026
Merged

christopherpickering merged 2 commits into
devfrom
feat/issue-802-settings-api-integration

Conversation

@vbeni30

@vbeni30 vbeni30 commented Sep 5, 2026

Copy link
Copy Markdown

Summary

  • Gate settings navigation tabs by backend permissions
  • Surface tag load failures instead of showing silent empty lists
  • Remove the /settings legacy rewrite so the Next.js page is canonical
  • Add frontend tests for the API client, server actions, and settings panels (reads, writes, validation, forbidden)

Test Plan

  • pnpm run frontend:typecheck
  • Vitest settings suite (45 tests)
  • dotnet test SettingsApiController (4 tests)

@Seme30 Seme30 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like the remaining #802 integration pass: permission-gated tabs, tag load errors, /settings rewrite removed, and tests for reads/writes/validation/forbidden. CI is green.

P2

  • frontend/app/settings/page.tsx:44-63 still Promise.alls every settings endpoint, including tabs the user cannot see. Users without Manage Global Site Settings / role-edit permissions will get a burst of 403s on every page load. Fetch only the panels the nav will show.

  • frontend/app/settings/layout.tsx:78 falls back to defaultTab = "roles" when navItems is empty, so a user with no settings permissions can still land on a hidden roles panel.

Not blocking merge for the #802 gaps this PR claims, but please fix the 403 fan-out if you touch the page again. This does not close #801 (/users/settings is still rewritten).

Share settings nav/access helpers between layout and page so SSR loads only endpoints for visible tabs. Users without role or site-settings permissions no longer trigger a 403 fan-out on page load, and users with no settings access see an empty state instead of defaulting to the hidden roles tab.
@Seme30

Seme30 commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Addressed by the last commit 7e9ef42 (7e9ef42).

The earlier P2 notes are covered: settings SSR now fetches only permission-visible panels, and users with no settings access get an empty state instead of a hidden roles tab. Ready for merge.

@christopherpickering
christopherpickering merged commit 70e0382 into dev Sep 25, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants