Skip to content

Add optional top_level_menu setting - #108

Merged
cruse1977 merged 2 commits into
mainfrom
feature
Sep 18, 2026
Merged

cruse1977 merged 2 commits into
mainfrom
feature

Conversation

@cruse1977

@cruse1977 cruse1977 commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Follow-up to #107 (merged before this commit landed on feature).

Fixes #104: setting PLUGINS_CONFIG['netbox_floorplan']['top_level_menu'] = True registers a dedicated top-level "Floorplan" menu instead of nesting "Floorplan Images" under NetBox's shared "Plugins" menu. Defaults to False, preserving current behaviour.

Fixes #94: FloorplanMapEditView inherited LoginRequiredMixin instead of PermissionRequiredMixin and referenced a nonexistent permission codename, so any logged-in user — including one with only view permission — could open the canvas editor. It now requires change_floorplan, and the Add/Edit/Delete Floorplan buttons on the site/location tab are hidden without the corresponding permission.

Verified against the live NetBox 4.7.1 stack in netbox-docker: default menu nesting unchanged, dedicated top-level menu renders correctly when enabled, full test suite passing (178/178).

🤖 Generated with Claude Code

cruse1977 and others added 2 commits September 18, 2026 12:27
Fixes #104. Setting PLUGINS_CONFIG['netbox_floorplan']['top_level_menu']
= True registers a dedicated top-level "Floorplan" menu instead of
nesting "Floorplan Images" under NetBox's shared "Plugins" menu.
Defaults to False, preserving current behaviour.

This is a deliberate exception to the plugin's previous no-settings
convention (AGENTS.md updated accordingly). Verified against the live
NetBox 4.7.1 stack in netbox-docker: default nesting is unchanged, and
enabling the setting renders the dedicated top-level menu correctly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Fixes #94. FloorplanMapEditView inherited LoginRequiredMixin instead of
PermissionRequiredMixin, so its permission_required attribute was never
consulted, and it referenced a permission codename, edit_floorplan,
that doesn't exist. Any logged-in user, including one with only view
permission, could open the drag-and-drop editor.

The view now requires netbox_floorplan.change_floorplan. The Add, Edit
and Delete Floorplan buttons on the site/location tab are also hidden
unless the viewer holds the corresponding permission, instead of
rendering unconditionally.

Saving and deleting were already enforced correctly server-side via the
REST API and NetBox's generic delete view; this closes the gap that let
an unauthorized user reach the editor UI at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@cruse1977
cruse1977 merged commit d5ceb46 into main Sep 18, 2026
6 checks passed
@cruse1977
cruse1977 deleted the feature branch September 18, 2026 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Could you please add top_level_menu config option Permission View also gives Change permission

1 participant