Skip to content

fix(api): Correct peer review authorization

Edouard Legoupil requested to merge fix-peer-review-permissions into main_dev

Created by: Edouard-Legoupil

The GET /api/proposals/{proposal_id}/peer-reviews endpoint was incorrectly restricted, causing a 403 Forbidden error for users who should have had access. The original logic only permitted the proposal's author to view the reviews.

This commit expands the authorization to grant access to:

  • The proposal owner
  • Any assigned peer reviewers
  • Users with the focal_point or admin role

This change ensures that all authorized parties can view the peer review status and feedback as intended.

  • Does my code meet the quality standards for releasing packages?
  • Does the reviewer have all the information to validate the features/issues without too much research?
  • Does the customer who will validate the associated tickets have the information to do so without wasting time?

Issues to validate to close :

  • issue #

Processed issues to keep open or in progress:

  • issue #

Checklist:

  • Does the package check go local?
  • Does the CI pass?
  • Are the added / fixed features documented, tested?
  • Are the added features / solved problems briefly presented in the PR message?
  • Are the changes related to tickets / issues that I have listed in the commits and in the PR itself?
  • Are the tickets in "review" mode in the Project Tracking Board?
  • Does each ticket, if it is to be closed after acceptance of the PR, contain a comment that tells how to validate it?

Merge request reports

Loading