Skip to content

Phase 5: Authorization and Policy Enforcement - #9

Merged
pcharbon70 merged 5 commits into
mainfrom
feature/phase-5-authorization-and-policy-enforcement
Mar 19, 2026
Merged

pcharbon70 merged 5 commits into
mainfrom
feature/phase-5-authorization-and-policy-enforcement

Conversation

@pcharbon70

Copy link
Copy Markdown
Collaborator

Summary

Implements Ash policy integration for UI resource access control and action authorization.

Section 5.1 - Policy Definitions

  • Common policy checks (user_active, user_role, screen_owner, environment)
  • UI.Screen policies (read, mount, create, update, destroy)
  • UI.Element policies (visibility, modification)
  • UI.Binding policies (evaluation, modification, data source access)
  • Cross-resource policy checks

Section 5.2 - Runtime Authorization

  • Mount authorization checking with redirect
  • Action authorization before execution
  • Data source read/write access checking
  • Policy result caching with TTL
  • Cache invalidation for user/resource changes
  • User extraction from LiveView socket
  • Authorization telemetry emission

Section 5.3 - Policy DSL Extensions

  • visible_if/2 for element visibility policies
  • editable_if/2 for element editability policies
  • accessible_if/2 for resource access policies
  • can_read_source/1 and can_write_source/1 for binding sources
  • Policy builders (build_visibility_policy, build_editability_policy, etc.)
  • all_of/1 and any_of/1 for combining policies
  • not_/1 for negating policies
  • time_policy/2 and environment_policy/1 helpers

Section 5.4 - Error Handling

  • AuthorizationError exception with structured fields
  • Error constructors (unauthenticated, forbidden, inactive)
  • User-friendly message formatting
  • Debug message formatting for logging
  • HTTP status code mapping (401, 403)
  • Translation support (English, Spanish, French, German)
  • Custom error page per resource

Section 5.5 - Integration Tests

  • Mount authorization integration scenarios
  • Action authorization integration scenarios
  • Data source authorization scenarios
  • Policy caching scenarios
  • End-to-end authorization flows
  • Error integration scenarios
  • Policy integration scenarios

Test plan

  • All policy definition tests pass
  • All runtime authorization tests pass
  • All policy DSL tests pass
  • All error handling tests pass
  • Integration tests validate end-to-end scenarios

Defined Ash policies for UI resources:
- Common policy checks (user_active, user_role, screen_owner, environment)
- UI.Screen policies (read, mount, create, update, destroy)
- UI.Element policies (visibility, modification)
- UI.Binding policies (evaluation, modification, data source access)
- Cross-resource policy checks (can_read_source, can_write_source, etc.)
- Tests for policy definitions
Implemented policy checking at runtime:
- Mount authorization checking with redirect
- Action authorization before execution
- Data source read/write access checking
- Policy result caching with TTL
- Cache invalidation for user/resource changes
- User extraction from LiveView socket
- Authorization telemetry emission
- Tests for runtime authorization
Created DSL extensions for common UI authorization patterns:
- visible_if/2 for element visibility policies
- editable_if/2 for element editability policies
- accessible_if/2 for resource access policies
- can_read_source/1 and can_write_source/1 for binding sources
- can_access_field/2 and can_execute_action/2 helpers
- Policy builders (build_visibility_policy, build_editability_policy, etc.)
- all_of/1 and any_of/1 for combining policies
- not_/1 for negating policies
- time_policy/2 and environment_policy/1 helpers
- Policy documentation helpers
- Tests for policy DSL
Implemented user-friendly authorization errors:
- AuthorizationError exception with resource, action, policy, reason fields
- Error constructors (unauthenticated, forbidden, inactive)
- User-friendly message formatting
- Debug message formatting for logging
- HTTP status code mapping (401, 403)
- Translation support (English, Spanish, French, German)
- Custom error page per resource
- Login redirect detection
- Recoverable error detection
- Tests for error handling
Added comprehensive integration tests for Phase 5:
- Mount authorization scenarios (authorized user, unauthorized redirect, unauthenticated login redirect)
- Action authorization scenarios (authorized execution, unauthorized errors, policy details, partial authorization)
- Data source authorization scenarios (authorized data display, unauthorized placeholder, no data leak, cross-resource)
- Policy caching scenarios (cache hits, resource invalidation, role invalidation, TTL respect)
- End-to-end authorization flows
- Error integration scenarios
- Policy integration scenarios
- Common policy checks
@pcharbon70
pcharbon70 merged commit 520cb7a into main Mar 19, 2026
4 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant