Repository navigation
Conversation
…opes in the roles modal Fixes the instance-wide grant sending domain=* for instance_admin instead of omitting it entirely. Adds a search filter over the granted-roles table, a confirmation step (listing what will be revoked) before an instance/domain-wide grant replaces a user's other roles, and hides/disables project or domain scope options once a wider role already covers them, with a tooltip explaining why.
…ide-role project grant An instance or domain admin role already covers every project, making a project-specific dropdown pointless and misleading on that row. Replaces it with the same read-only badge used in the Settings > Users roles modal (InstanceUsersRoleBadge), showing only the highest rank when a row somehow holds both.
The "Your role" column explicitly suppressed DisplayRole's icon, so every row showed plain text while the role dropdown/badge elsewhere in the app always pairs the label with its icon.
…a wrapper b-dropdown sets inheritAttrs:false and spreads attrs onto its outer wrapper, not the inner toggle button, so a bare `title` bound on DropdownSelector or ProjectDropdownSelector never reached the focusable control a keyboard or screen-reader user actually lands on. Adds a `toggleAttrs` passthrough on DropdownSelector (b-dropdown's own prop for this) and a `title` prop on ProjectDropdownSelector that forwards it that way.
…Dropdown ProjectUsersList.vue stopped passing it once a wide-role project row got its own read-only badge instead of this dropdown; nothing else in src/ passed it either, leaving the prop, its "Inherited" branch, and the i18n string as unreachable code.
A domain-admin-only viewer under OAuth always gets an empty scope picker
regardless of the target's grants (no instance/domain entry without
isInstanceAdmin, no project entry under OAuth), but scopePickerDisabledTitle
blamed the target ("already has a role on every project") instead of the
viewer's own permission ceiling. Checks that case first now.
Also documents two known limitations with TODO/comment notes rather than
fixing them (no domain model to filter by yet; the grant-time cascade-revoke
is enforced only in this component, not server-side).
TinyPagination's row-number input is only disabled, not hidden, at zero rows, so it still shows a literal "0" next to the "of 0 users" label, reading as "0 of 0 users".
A duplicate username only showed a toast, with no indication on the field itself; the username input now gets :state="false" and an inline message, cleared as soon as the username is edited again.
Each item embedded a <strong>verb</strong> as a raw HTML string rendered via
v-html, which vue-i18n flags as an XSS-prone pattern. Reworks each string
around a {verb} slot and renders through i18n-t, same pattern the modal
title already uses for its own embedded component.
type="email" already blocked the save via native checkValidity(), but nothing in the page said why - only the browser's own tooltip. Adds a visible inline message, same pattern as the password-mismatch field.
…te text - Refresh the user data every time the roles modal opens, instead of trusting whatever stale `user` prop the parent happened to have (a role changed elsewhere, e.g. via the CLI, while the modal sat open went unnoticed). - Confirm before revoking an instance/domain admin role, since it removes access to every project it covered, not just one row; plain project revokes stay single-click. - "This user has no project role grants yet." reworded to "no role grants", since the same modal also manages domain and instance grants.
The backend now deletes the grants a wide role replaces when it is granted: project grants, and domain admin under instance admin. The roles modal no longer revokes them itself after granting, which also drops the partial-failure path and its cleanup error toast. The confirmation still lists what will be replaced, and now says those grants will not come back if the role is revoked later.
Merged
4 tasks done
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
domainfor instance_admin instead of sending*; adds a search filter; confirms (listing what gets revoked) before an instance/domain-wide grant replaces other roles; hides/disables project or domain scope options once a wider role already covers them, with an explanatory tooltip when the picker ends up disabled.Test plan
/#/projectsUploading Screencast from 2026-10-07 10-27-51.webm…