Skip to content

Make rebuilding an onboarding path a PM action - #262

Open
DavidLeuter wants to merge 3 commits into
devfrom
feature/pm-only-path-rebuild
Open

DavidLeuter wants to merge 3 commits into
devfrom
feature/pm-only-path-rebuild

Conversation

@DavidLeuter

@DavidLeuter DavidLeuter commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Every member could rebuild their own onboarding path at any time (POST /projects/{projectId}/onboarding/me/path/personalize), which replaces the path and throws their progress away. They could get the same result by deleting their path (DELETE /onboarding/me/path) and building a new one. Rebuilding a path should be the project manager's call.

Changes

  • New PM endpoint: POST /api/v1/projects/{projectId}/onboarding/users/{userId}/path/personalize, guarded by @projectAuth.canManageProject (the project's manager or an admin). It runs through OnboardingGenerationRegistry under the member's auth id, so the member's own onboarding page attaches to it like to a run they started. Unknown user → 404; member not in the project → 403 (existing personalize check).
  • /me/path/personalize guard: returns 403 when no generation is running, the caller's path has at least one phase, and the caller does not manage the project. Still allowed for members:
    • building their first path,
    • retrying a path whose every phase failed to generate (it holds no progress),
    • attaching to a running generation (including one a PM started).
  • DELETE /onboarding/me/path: now hasAnyRole('PM', 'ADMIN') instead of hasRole('USER'). No client calls it for members.
  • UserApi.getAuthIdByUserId (backed by the existing UserRepository.findAuthIdById) and OnboardingPathService.hasBuiltPathForMe.

Frontend counterpart: SprintStartProject/sprintstart-frontend#269 (removes the member's Rebuild button, adds it to the PM's member page).

Tests

  • New controller tests: a PM rebuild starts under the member's auth id; non-managers get 403; unknown member gets 404; a member rebuilding a built path gets 403; a project manager may rebuild their own path; a running generation can still be attached to; a plain member can't delete their path.
  • New service tests for hasBuiltPathForMe (phases / empty path / no path / unknown user).
  • ./gradlew check: 3413 of 3415 tests green, ktlint + detekt clean. The two failures are the known local-only OnDiskOperationsTest > Exec cases (the temp dir sits inside a git repo on this machine); unrelated to this change.

🤖 Generated with Claude Code

DavidLeuter and others added 3 commits September 26, 2026 15:38
A member could replace their own path (and lose their progress) at any
time through /me/path/personalize. Members now only build their first
path there; replacing an existing one is refused with 403 unless the
caller manages the project. Watching a running generation stays open.

New POST /projects/{projectId}/onboarding/users/{userId}/path/personalize
lets the project's manager (or an admin) rebuild a member's path. It runs
through the same generation registry under the member's auth id, so the
member's own page attaches to it like to one they started.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An empty path holds no progress, so retrying it is not a rebuild. The
guard on /me/path/personalize now only protects a path with phases.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A member deleting their path and building a new one was the same rebuild
that is now the project manager's call. DELETE /onboarding/me/path now
requires PM or ADMIN; the frontend never called it for members.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant