Skip to content

feat(users): manage instance user accounts and roles from Settings > Users - #519

Merged
caro3801 merged 14 commits into
mainfrom
feat/instance-user-management
Oct 2, 2026
Merged

caro3801 merged 14 commits into
mainfrom
feat/instance-user-management

Conversation

@caro3801

@caro3801 caro3801 commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds Settings > Users, an instance-wide page to manage user accounts and their roles (ICIJ/datashare#2387, sub-issues #2388-#2395, #2404).

The big move: from the project Users tab to Settings > Users

Account management used to live in each project's Users tab. It now lives in one place, Settings > Users:

Before (project Users tab) Now
Create a user (ProjectViewEditUsersCreateModal) Settings > Users, SettingsViewUsersCreateModal (moved and reworked, then opens the user's roles)
Delete a user (ProjectViewEditUsersDeleteModal) Settings > Users, SettingsViewUsersDeleteModal
- Edit a user (new, SettingsViewUsersEditModal)
- Grant/revoke project, domain and instance roles (new, SettingsViewUsersRolesModal)
Role assignment on the project Stays in the project Users tab, which is now role assignment only

The project Users tab keeps a role column: the user's instance and domain admin roles as badges, then a dropdown with their role on this project only ("Inherited" when their access comes only from one of those badges). Users are added to or removed from the project by picking a role or "No role". Both pages share the same list logic (usePaginatedUsers).

Main features

  • List of all users, with search, sort, pagination (kept in the URL), and role badges per user. Users with no role are listed too.
  • Create an account, then land on its roles modal.
  • Edit an account's name, email and password (with an optional password reset).
  • Delete an account, which also removes all of its role grants.
  • Manage roles of a user: project roles, domain admin and instance admin, with search over the granted scopes.
  • Routed modals: every modal has its own URL (/settings/users/create, /settings/users/(edit|manage|delete)/<uid>), so it can be linked to or reloaded. An unknown uid shows "User does not exist."
  • Permissions match the backend @Policy checks: instance admins manage accounts and instance/domain admin grants; domain admins see the list and manage project roles. Nobody can delete their own account or revoke their own instance admin role.
  • Auth modes: create, edit and delete only exist with form/basic auth. Under OAuth, the identity provider owns accounts and project membership, so the roles modal only offers new instance/domain grants.
  • Unsupported listing: when the users provider can't list accounts (501), both pages say so instead of showing an empty list or an error.

How to review

The history is split into 14 commits, one feature each, in dependency order. Each commit builds, carries its own specs and strings, and can be read on its own.

Commit Files worth reading
test(project-edit): spec timeout fix (also fails on main) ProjectViewEditDetails.spec.js
chore: .gitignore .gitignore
feat(api) src/api/index.js
feat(policies) usePolicies.js (isDomainAdmin, isInstanceAdmin now a computed), useAuth.js (isCurrentUser)
refactor(project) ProjectButton.vue, ProjectLabel.vue, utils/projects.js, ProjectDropdownSelector* (placeholder), PageTableGeneric.vue (top-row slot)
fix(form) FormInputPassword.vue, DisplayUserAvatar.vue
feat(roles) enums/roles.js (parsing, ordering, icon/color), DisplayRole.vue, ProjectRoleThumbnail.vue, InstanceUsersRoleBadge(s).vue
refactor(users): paginated list usePaginatedUsers.js, InstanceUsersList.vue, InstanceUsersActions.vue, store/modules/app.js (getSettings falls back to view defaults)
refactor(project-users) ProjectViewEditUsers.vue, ProjectUsersList.vue, ProjectUsersRoleDropdown.vue (old create/delete modals removed)
feat(users): create SettingsViewUsersCreateModal.vue, usePasswordConfirm.js
feat(users): edit SettingsViewUsersEditModal.vue, SettingsViewUsersNotFound.vue
feat(users): delete SettingsViewUsersDeleteModal.vue
feat(users): roles SettingsViewUsersRolesModal.vue (the densest part)
feat(users): page SettingsViewUsers.vue (routed modals, refreshes, unsupported state), SettingsView.vue, router/index.js

The four files in bold carry most of the logic. Specs mirror each file under tests/unit/specs/.

Side effects outside the users pages

  • ProjectDropdownSelector now shows "Select a project" when nothing is selected, including in the search bar.
  • getSettings falls back to a view's defaults, so adding a view no longer needs a SETTINGS_VERSION bump.

known limitations :
User pagination search is not optimized: SettingsViewUsers.vue, fetchRoutedUser: finding a user by uid searches with q=uid and only checks the first 100 results for an exact match.

Settings > users
Screenshot from 2026-10-02 10-28-54
Screenshot from 2026-10-02 10-29-00
Screenshot from 2026-10-02 10-29-10
Screenshot from 2026-10-02 10-29-37
Screenshot from 2026-10-02 10-29-42

Project > users
Screenshot from 2026-10-02 10-30-09
Screenshot from 2026-10-02 10-30-13

@caro3801 caro3801 self-assigned this Sep 21, 2026
@caro3801
caro3801 force-pushed the feat/instance-user-management branch from e89cd76 to bc27567 Compare October 2, 2026 12:08
* resolves to `{ items, total }`.
* @param {string|Ref<string>|Function} options.errorMessage - Toasted when a load fails.
*/
export function usePaginatedUsers(view, { load, errorMessage }) {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hint: might be a job for the backend at some point.

@caro3801
caro3801 force-pushed the feat/instance-user-management branch from 3d2cf54 to 4832dc8 Compare October 2, 2026 12:59
@caro3801
caro3801 requested a review from a team October 2, 2026 13:09

@pirhoo pirhoo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot @caro3801 for this big piece of work, and for the thorough tests! A few comments below.

Comment thread src/views/Settings/SettingsView/SettingsViewUsersDeleteModal.vue Outdated
Comment thread src/views/Settings/SettingsView/SettingsViewUsersRolesModal.vue Outdated
Comment thread src/enums/roles.js
Comment thread src/views/Settings/SettingsView/SettingsViewUsers.vue
Comment thread src/composables/usePaginatedUsers.js Outdated
Comment thread src/composables/usePaginatedUsers.js Outdated
@caro3801
caro3801 force-pushed the feat/instance-user-management branch from 4832dc8 to f00c3b5 Compare October 2, 2026 13:45
@caro3801
caro3801 requested a review from pirhoo October 2, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants