Skip to content

fix(concierge): admit only admin and support users until access groups are set - #551

Closed
camreeves wants to merge 1 commit into
developfrom
fix/concierge-default-access
Closed

camreeves wants to merge 1 commit into
developfrom
fix/concierge-default-access

Conversation

@camreeves

Copy link
Copy Markdown
Contributor

What

The shared route guard (libs/components/src/lib/authorised-user.guard.ts) admitted everyone when app.allow_access_groups was unset, and concierge ships with it unset. Measured on the e2e stack with a plain staff user (sys_admin: false, no groups): the full concierge shell with 13 sidebar links, including everyone's desk and parking bookings, the visitor list, catering orders, the staff directory and the contact tracing report (CON-B1 on #497).

The guard now takes default groups from the app's PLACEOS_APP_ACCESS provider and uses them only while no groups are configured. Concierge declares placeos_admin and placeos_support, which every admin and support user carries (StaffUser derives them from sys_admin / support), so:

  • an unconfigured deployment keeps working for the people who set it up, and refuses plain staff with the usual /unauthorised bounce;
  • a deployment that has set app.allow_access_groups is unaffected, the configured list replaces the defaults;
  • the other apps provide no PLACEOS_APP_ACCESS and behave exactly as before.

docs/settings/concierge.md gets a row for allow_access_groups saying so.

This is the call for now; if a deployment relies on the old open default it is one setting to restore it.

Verified

  • bunx nx test components: 311 pass, with two new cases (defaults refuse a plain user and admit support; configured groups take precedence over defaults).
  • e2e on the stack: concierge-access.spec.ts 5 of 5, including CON-B1 lifted on test(e2e): workplace and concierge [2026-09-18] #497 (a plain staff user lands on /unauthorised) and CON-AUTH-01/02 unchanged (admin in; user outside a configured group refused).

…s are set

The shared route guard let everyone in when `app.allow_access_groups` was
unset, and concierge ships with it unset, so any signed-in staff member
got the front desk: everyone's desk and parking bookings, the visitor
list, catering orders, the staff directory and the reports.

The guard now takes default groups from the app's `PLACEOS_APP_ACCESS`
provider and uses them only while no groups are configured. Concierge
declares `placeos_admin` and `placeos_support`, which every admin and
support user carries, so an unconfigured deployment keeps working for the
people who set it up and refuses plain staff. A configured list replaces
the defaults, and the other apps provide nothing and behave as before.
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
frontend-templates Ignored Ignored Preview Oct 7, 2026 11:50pm UTC

camreeves added a commit that referenced this pull request Oct 7, 2026
… tenant

CON-B1 loses its guard: concierge now admits admin and support users
only until app.allow_access_groups is set (develop, #551), so a plain
staff user lands on /unauthorised. The test waits for that bounce or the
shell, whichever comes first.

CON-B3 asserts what can be true: a booking has no asset name column, so
the listing resolves the locker's name from the lockers it has loaded
(develop, #552). CON-LOCK-03 asserts the name too.

The calendar-backed rows run against the Microsoft 365 sandbox tenant
the stack can now be seeded with (develop, e2e/calendar-tenant), and
skip without it. calendar.seed.ts owns the one room with a real mailbox
and the events the specs put on it; the fixtures gain the calendar
identity, an admin whose address is a mailbox there, because staff-api
only lets a user host for themselves. CON-DAY-02/03/04, CON-STAFF-01/02
and CON-REP-02 are written; CON-DAY-05 is not yet, and CON-DAY-06/07
wait on the approvals driver.
@MrYuion

MrYuion commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

This is the expected behaviour. It will break existing clients if we change it.

@MrYuion MrYuion closed this Oct 8, 2026
@MrYuion
MrYuion deleted the fix/concierge-default-access branch October 8, 2026 00:26
camreeves added a commit that referenced this pull request Oct 8, 2026
#551 was closed: with no access group configured concierge admits every
signed-in user, and that default stays because existing deployments rely on
it. CON-B1 asserted the opposite and would have failed on every run.

The row now asserts the decided behaviour: a plain staff user is given the
shell, is not sent to /unauthorised, and is still not offered the management
pages, which the sidebar withholds on its own is_admin check. CON-AUTH-02
remains the test of the guard with a group set. The file header no longer
describes the default as a hole.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants