Fix #423: org membership rail #429
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!429
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-423"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #423 — owner profile Organizations membership list (backend rail was missing).
DECISION (endpoint vs profile field): dedicated endpoint GET /api/v1/users/{principal}/orgs over Service.MemberOrgsFor — NOT a member_orgs profile field. Rationale: core internal/api must never import identity (law 8 — a field needs a new seam); the endpoint keeps the LIST-plus-probes cost off every profile GET (law 6) and leaves profileETag untouched (no #382 entanglement). Visibility: no filtering — every containing roster served to read-authorized callers (anonymous needs anonymous_read, the profile/members gate); org visibility governs repos, not roster facts. Org profiles omit the section (member principals are email spellings, not routable owner slugs per #370 — roster lives at organization settings). Full rationale in docs/features/01_identity_permissions.md §Decisions.
What lands:
Tests: identity -race green, routeUserOrgs 100%, package 95.7% (≥95 gate); node 891 pass / 0 fail (2 server-smoke tests skip on cold port — :8080 here answers from a foreign live instance, untouched); vite build green; gofmt/vet clean; no new deps. Browser: not driven (shared daemon blocks loopback per task note) — reasoning + headless coverage only.