Fix #361: team subject picker #368

Merged
crueber merged 2 commits from fix/issue-361 into main 2026-09-12 01:27:16 +00:00
Owner

Fixes #361 (survey #349 candidate 4): team-subject bindings are discoverable from the Access tab.

  • On org-owned repos the add-binding form gains a team dropdown fed by the owner org's team list (client.orgs.teams.list, one cached GET); picking a team composes team:org/slug into the subject field. 404/403/empty degrade to the text-only form, so non-org owners see no change.
  • Free-text entry still works; spelling validates client-side (web/src/lib/access.js, charset mirrors of identity.ValidOrg/ValidSlug) with a friendly note — the server still revalidates on PUT.
  • Native select, no popover/CSS, no team mutations from the picker; no backend change; no new deps.
  • Tests: new web/test/unit/access-subject.test.js (12 tests: picker/compose/validate + Access.jsx wiring guards); full web suite 712/712 green (3 smoke tests need a live non-setup server — the :8080 instance here answers 503 setup-only, pre-existing/environmental); vite + esbuild build clean.
  • Law-12 decision appended to docs/features/01_identity_permissions.md Decisions.
Fixes #361 (survey #349 candidate 4): team-subject bindings are discoverable from the Access tab. - On org-owned repos the add-binding form gains a team dropdown fed by the owner org's team list (`client.orgs.teams.list`, one cached GET); picking a team composes `team:org/slug` into the subject field. 404/403/empty degrade to the text-only form, so non-org owners see no change. - Free-text entry still works; spelling validates client-side (`web/src/lib/access.js`, charset mirrors of `identity.ValidOrg`/`ValidSlug`) with a friendly note — the server still revalidates on PUT. - Native select, no popover/CSS, no team mutations from the picker; no backend change; no new deps. - Tests: new `web/test/unit/access-subject.test.js` (12 tests: picker/compose/validate + Access.jsx wiring guards); full web suite 712/712 green (3 smoke tests need a live non-setup server — the :8080 instance here answers 503 setup-only, pre-existing/environmental); vite + esbuild build clean. - Law-12 decision appended to `docs/features/01_identity_permissions.md` Decisions.
Access-tab add-binding form gains a team dropdown on org-owned repos
(features/01 §9): the owner org roster via client.orgs.teams.list
composes team:org/slug into the subject field; free text stays the
fallback and spelling validates client-side (web/src/lib/access.js,
node --test) with a friendly note. No backend change; no new deps;
no new CSS (native select, #278 unaffected). Decision appended to
docs/features/01_identity_permissions.md Decisions. Survey: #349
candidate 4.
Review finding on fix/issue-361: the picker fetched the roster for
every non-empty owner, wasting a 404 GET on user-owned repos. An org
slug (identity.ValidOrg) can never contain '@', so email owners skip
via headless shouldFetchTeams; 404/403/empty still degrade. Doc
decision updated in the same change (law 12).
Sign in to join this conversation.
No description provided.