Skip to content

refactor(auth): Remove role-based authorization

Edouard Legoupil requested to merge fix-remove-role-based-access into main_dev

Created by: Edouard-Legoupil

This commit removes all user role-based logic from the application. The authorization for accessing proposal-related information is now based solely on proposal ownership or reviewer assignment.

Specifically, the following changes were made:

  • The get_status_history and get_peer_reviews endpoints in backend/api/proposals.py no longer check for "focal_point" or "admin" roles.

  • The frontend has been updated to allow a proposal to be moved directly from the "Draft" to the "Submitted" status, bypassing the peer review process if desired.

  • Does my code meet the quality standards for releasing packages?

  • Does the reviewer have all the information to validate the features/issues without too much research?

  • Does the customer who will validate the associated tickets have the information to do so without wasting time?

Issues to validate to close :

  • issue #

Processed issues to keep open or in progress:

  • issue #

Checklist:

  • Does the package check go local?
  • Does the CI pass?
  • Are the added / fixed features documented, tested?
  • Are the added features / solved problems briefly presented in the PR message?
  • Are the changes related to tickets / issues that I have listed in the commits and in the PR itself?
  • Are the tickets in "review" mode in the Project Tracking Board?
  • Does each ticket, if it is to be closed after acceptance of the PR, contain a comment that tells how to validate it?

Merge request reports

Loading