Skip to content

Task - implement library updates #319

Description

@MaferMazu

Description

This task focuses exclusively on the views and components related to Library Updates within the Authoring MFE. The goal is to ensure that users with these roles interact only with the permitted elements, by applying “read-only” states for Course Auditors and enabling full management actions for Course Editors, as defined by the permission matrix.

Permission Matrix

Category Permission Course Editor Course Auditor
Library Updates courses.manage_library_updates ✅ ❌
courses.view_library_updates ✅ ✅

Approved Design: Figma

Activity

  1. moved this to In Grooming in RBAC AuthZ Boardon Aug 4, 2026
  2. BryanttV commented on Aug 10, 2026

    @BryanttV
    Contributor

    Hi @dcoa, could you help me refine this issue? It seems to me that we'll also need to add a new read-only permission here.

    cc @gviedma-aulasneo

  3. dcoa commented on Aug 11, 2026

    @dcoa
    Contributor

    Yes, we should add a view permission to distinguish unauthorized users from Course Auditors.

    Refinement

    Acceptance criteria

    1. A user with courses.view_library_updates (but without courses.manage_library_updates)
      can open the Libraries page and the "Review Content Updates" tab.
    2. On each update card, the Update (accept) and Ignore buttons are
      disabled.
    3. The preview modal's Accept changes / Ignore changes buttons (and the
      locally-modified variants "Update to published library content" / "Keep course
      content") are disabled for read-only users.
    4. Hovering any disabled button shows the tooltip:
      Your role doesn't include permission to do this. Contact your org admin to request access
    5. "Review Updates" (open preview) remains enabled for read-only users — viewing
      is allowed.
    6. A user without courses.view_library_updates still gets the existing
      PermissionDeniedAlert.
    7. The course header "Libraries" menu link is shown to users with the view
      permission (so view-only users can actually reach the page).

    Implementation tasks (frontend-app-authoring)

    1. Authz plumbing

    • src/authz/constants.ts: add VIEW_LIBRARY_UPDATES: 'courses.view_library_updates'.
    • src/authz/permissionHelpers.ts: add canViewLibraryUpdates to
      getLibraryUpdatesPermissions() (view + manage, both course-scoped).
    • src/authz/permissionHelpers.test.ts: update the assertion for the new shape.

    2. Read-only message

    • src/generic/messages.ts: add readOnlyTooltip with the exact copy above
      (description included for translators). Shared so both the review tab and the
      preview modal use the same string.

    3. Page gating + read-only propagation

    • src/course-libraries/CourseLibraries.tsx:
      • gate on canViewLibraryUpdates (PermissionDeniedAlert otherwise);
      • compute readOnly = !canManageLibraryUpdates;
      • pass readOnly to ReviewTabContent.
    • src/header/hooks.tsx: show the "Libraries" content-menu link based on
      canViewLibraryUpdates instead of canManageLibraryUpdates.

    4. Review tab card actions

    • src/course-libraries/ReviewTabContent.tsx:
      • thread readOnly through ReviewTabContent → ItemReviewList;
      • disable "Update" (LoadingButton) and "Ignore" buttons when read-only;
      • wrap the disabled buttons in OverlayTrigger/Tooltip (via a <span>, the
        established pattern from src/course-unit/add-component/add-component-btn);
      • keep "Review Updates" enabled;
      • pass readOnly into the preview modal.

    5. Preview modal

    • src/course-unit/preview-changes/index.tsx:
      • add optional readOnly prop (default false) so existing callers
        (OutlineNode.tsx, LibraryReferenceCard.tsx, iframe wrapper) are unaffected;
      • disable + tooltip on "Accept changes"/"Ignore changes" and the locally
        modified variants "Update to published library content"/"Keep course content".

    6. Tests

    • src/course-libraries/CourseLibraries.test.tsx:
      • default permission mock includes canViewLibraryUpdates: true;
      • permission-denied test now keys off canViewLibraryUpdates: false;
      • new tests: read-only user sees disabled Update/Ignore with tooltip on hover;
        preview modal buttons disabled with tooltip for read-only user.
    • src/course-unit/preview-changes/index.test.tsx: render modal directly with
      readOnly and assert disabled buttons + tooltip.
    • src/header/hooks.test.tsx: mocks switched to canViewLibraryUpdates.
  4. moved this from In Grooming to Blocked in RBAC AuthZ Boardon Aug 13, 2026
  5. dcoa commented on Aug 25, 2026

    @dcoa
    Contributor

    I want to verify one last thing here and that is the out of sync Alert that is displayed in the course outline and libraries updates. There is not indication of what to do with it for Course Auditor in the Figma, and keep it does not cause any harm because it redirects to Library Updates page. However, I feel the message misleading for that specific role because it says "Review updates to accept or ignore changes" -> Action that cannot perform

    Image

    I wonder if we would like to keep it as it is, or we should either hide the Alert or remove the review part of message for read only permissions.

    @BryanttV @gviedma-aulasneo

  6. moved this from Blocked to In Progress in RBAC AuthZ Boardon Aug 27, 2026
  7. gviedma-aulasneo commented on Aug 27, 2026

    @gviedma-aulasneo

    @dcoa Do we use that message somewhere else? If not, I think we can change the last sentence to 'Review updates to see what changed' and it may be less misleading.

  8. moved this from In Progress to Ready for Review in RBAC AuthZ Boardon Sep 1, 2026
  9. moved this from Ready for Review to Blocked in RBAC AuthZ Boardon Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

willowReleased in Willow

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions