Make rebuilding an onboarding path a PM action - #262
Open
DavidLeuter wants to merge 3 commits into
Open
DavidLeuter wants to merge 3 commits into
DavidLeuter wants to merge 3 commits into
Conversation
A member could replace their own path (and lose their progress) at any
time through /me/path/personalize. Members now only build their first
path there; replacing an existing one is refused with 403 unless the
caller manages the project. Watching a running generation stays open.
New POST /projects/{projectId}/onboarding/users/{userId}/path/personalize
lets the project's manager (or an admin) rebuild a member's path. It runs
through the same generation registry under the member's auth id, so the
member's own page attaches to it like to one they started.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An empty path holds no progress, so retrying it is not a rebuild. The guard on /me/path/personalize now only protects a path with phases. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A member deleting their path and building a new one was the same rebuild that is now the project manager's call. DELETE /onboarding/me/path now requires PM or ADMIN; the frontend never called it for members. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Every member could rebuild their own onboarding path at any time (
POST /projects/{projectId}/onboarding/me/path/personalize), which replaces the path and throws their progress away. They could get the same result by deleting their path (DELETE /onboarding/me/path) and building a new one. Rebuilding a path should be the project manager's call.Changes
POST /api/v1/projects/{projectId}/onboarding/users/{userId}/path/personalize, guarded by@projectAuth.canManageProject(the project's manager or an admin). It runs throughOnboardingGenerationRegistryunder the member's auth id, so the member's own onboarding page attaches to it like to a run they started. Unknown user → 404; member not in the project → 403 (existingpersonalizecheck)./me/path/personalizeguard: returns 403 when no generation is running, the caller's path has at least one phase, and the caller does not manage the project. Still allowed for members:DELETE /onboarding/me/path: nowhasAnyRole('PM', 'ADMIN')instead ofhasRole('USER'). No client calls it for members.UserApi.getAuthIdByUserId(backed by the existingUserRepository.findAuthIdById) andOnboardingPathService.hasBuiltPathForMe.Frontend counterpart: SprintStartProject/sprintstart-frontend#269 (removes the member's Rebuild button, adds it to the PM's member page).
Tests
hasBuiltPathForMe(phases / empty path / no path / unknown user)../gradlew check: 3413 of 3415 tests green, ktlint + detekt clean. The two failures are the known local-onlyOnDiskOperationsTest > Execcases (the temp dir sits inside a git repo on this machine); unrelated to this change.🤖 Generated with Claude Code