Skip to content

Frontend: Implement Granular Permissions in Authoring UI (Course Editor/Auditor) #284

Description

@MaferMazu

Overview

Following the approved design and UX audit for roles (Course Editor/Auditor), this task involves the technical implementation of granular permission checks across the Authoring frontend. The goal is to ensure the UI accurately reflects user capabilities by toggling the visibility and interactivity of components.

Scope of Work

  • Integration of Permission Logic: Implement conditional rendering based on granular permission flags.
  • UI Controls: Apply "no-access" states (disabled buttons, hidden menus, or read-only views) as defined in the design proposal.
  • Course Editor/Auditor Specifics: Ensure specific restrictions for these roles are enforced across all Authoring modules.
  • Error Handling: Gracefully handle edge cases where a user might attempt to access a restricted route via URL.

Resources

Success Criteria

  • The UI correctly hides or disables features based on the user's granular permissions.
  • No "dead ends" are present; users see clear indicators (tooltips/states) when an action is restricted.

Details

Category Permission Course Editor Course Auditor
Tags & taxonomies Manage tags ✔ ❌
Course updates & handouts View updates ✔ ✔
Manage course updates ✔ ❌
Advanced & certificates Manage advanced settings ❌ ❌
Manage certificates ❌ ❌
Course Access & content View course ✔ ✔
Create course ❌ ❌
Publish content ❌ ❌
Edit content ✔ ❌
Files View files ✔ ✔
Create files ✔ ❌
Edit files ✔ ❌
Delete files ❌ ❌
Schedule & details View schedule ✔ ✔
Edit schedule ❌ ❌
View details ✔ ✔
Edit details ✔ ❌
Library updates Review library updates ✔ ❌
Grading View grading ✔ ✔
Edit grading settings ✔ ❌
Pages & resources View pages and resources ✔ ✔
Manage pages & resources ✔ ❌
Other View checklists ✔ ✔
View global staff & super admins ✔ ❌
Import / export Import course ❌ ❌
Export course ❌ ❌
Export tags ❌ ❌
Course team & groups View course team ✔ ✔
Manage group config ✔ ❌
Manage course team ❌ ❌

Activity

  1. moved this from Blocked to Ready for Development in RBAC AuthZ Boardon Aug 4, 2026
  2. dcoa commented on Aug 10, 2026

    @dcoa
    Contributor

    @BryanttV there is a reason why course outline does not have a card https://www.figma.com/design/onU2END2OXaF7RRLWEHsZI/AuthZ---v2?node-id=6068-9249&p=f&t=uWec6UX7AZNVwKDN-0 ? is it still in review?

    That is specially important for #286 where Course and Unit Overview are highlighted as critical for the audit.

  3. BryanttV commented on Aug 10, 2026

    @BryanttV
    Contributor

    @dcoa, You're right, I just created a new task for that (#383). Thanks for reminding me.

  4. moved this from Ready for Development to In Progress in RBAC AuthZ Boardon Aug 18, 2026
  5. moved this from In Progress to No status in RBAC AuthZ Boardon Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions