Repository navigation
Conversation
…s are set The shared route guard let everyone in when `app.allow_access_groups` was unset, and concierge ships with it unset, so any signed-in staff member got the front desk: everyone's desk and parking bookings, the visitor list, catering orders, the staff directory and the reports. The guard now takes default groups from the app's `PLACEOS_APP_ACCESS` provider and uses them only while no groups are configured. Concierge declares `placeos_admin` and `placeos_support`, which every admin and support user carries, so an unconfigured deployment keeps working for the people who set it up and refuses plain staff. A configured list replaces the defaults, and the other apps provide nothing and behave as before.
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
camreeves
added a commit
that referenced
this pull request
Oct 7, 2026
… tenant CON-B1 loses its guard: concierge now admits admin and support users only until app.allow_access_groups is set (develop, #551), so a plain staff user lands on /unauthorised. The test waits for that bounce or the shell, whichever comes first. CON-B3 asserts what can be true: a booking has no asset name column, so the listing resolves the locker's name from the lockers it has loaded (develop, #552). CON-LOCK-03 asserts the name too. The calendar-backed rows run against the Microsoft 365 sandbox tenant the stack can now be seeded with (develop, e2e/calendar-tenant), and skip without it. calendar.seed.ts owns the one room with a real mailbox and the events the specs put on it; the fixtures gain the calendar identity, an admin whose address is a mailbox there, because staff-api only lets a user host for themselves. CON-DAY-02/03/04, CON-STAFF-01/02 and CON-REP-02 are written; CON-DAY-05 is not yet, and CON-DAY-06/07 wait on the approvals driver.
Collaborator
|
This is the expected behaviour. It will break existing clients if we change it. |
camreeves
added a commit
that referenced
this pull request
Oct 8, 2026
#551 was closed: with no access group configured concierge admits every signed-in user, and that default stays because existing deployments rely on it. CON-B1 asserted the opposite and would have failed on every run. The row now asserts the decided behaviour: a plain staff user is given the shell, is not sent to /unauthorised, and is still not offered the management pages, which the sidebar withholds on its own is_admin check. CON-AUTH-02 remains the test of the guard with a group set. The file header no longer describes the default as a hole.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The shared route guard (
libs/components/src/lib/authorised-user.guard.ts) admitted everyone whenapp.allow_access_groupswas unset, and concierge ships with it unset. Measured on the e2e stack with a plain staff user (sys_admin: false, no groups): the full concierge shell with 13 sidebar links, including everyone's desk and parking bookings, the visitor list, catering orders, the staff directory and the contact tracing report (CON-B1 on #497).The guard now takes default groups from the app's
PLACEOS_APP_ACCESSprovider and uses them only while no groups are configured. Concierge declaresplaceos_adminandplaceos_support, which every admin and support user carries (StaffUserderives them fromsys_admin/support), so:/unauthorisedbounce;app.allow_access_groupsis unaffected, the configured list replaces the defaults;PLACEOS_APP_ACCESSand behave exactly as before.docs/settings/concierge.mdgets a row forallow_access_groupssaying so.This is the call for now; if a deployment relies on the old open default it is one setting to restore it.
Verified
bunx nx test components: 311 pass, with two new cases (defaults refuse a plain user and admit support; configured groups take precedence over defaults).concierge-access.spec.ts5 of 5, including CON-B1 lifted on test(e2e): workplace and concierge [2026-09-18] #497 (a plain staff user lands on/unauthorised) and CON-AUTH-01/02 unchanged (admin in; user outside a configured group refused).