Repository navigation
Task - implement library updates #319
Description
Activity
Hi @dcoa, could you help me refine this issue? It seems to me that we'll also need to add a new read-only permission here.
Yes, we should add a view permission to distinguish unauthorized users from Course Auditors.
Refinement
Acceptance criteria
- A user with
courses.view_library_updates(but withoutcourses.manage_library_updates)
can open the Libraries page and the "Review Content Updates" tab. - On each update card, the Update (accept) and Ignore buttons are
disabled. - The preview modal's Accept changes / Ignore changes buttons (and the
locally-modified variants "Update to published library content" / "Keep course
content") are disabled for read-only users. - Hovering any disabled button shows the tooltip:
Your role doesn't include permission to do this. Contact your org admin to request access - "Review Updates" (open preview) remains enabled for read-only users — viewing
is allowed. - A user without
courses.view_library_updatesstill gets the existing
PermissionDeniedAlert. - The course header "Libraries" menu link is shown to users with the view
permission (so view-only users can actually reach the page).
Implementation tasks (frontend-app-authoring)
1. Authz plumbing
src/authz/constants.ts: addVIEW_LIBRARY_UPDATES: 'courses.view_library_updates'.src/authz/permissionHelpers.ts: addcanViewLibraryUpdatesto
getLibraryUpdatesPermissions()(view + manage, both course-scoped).src/authz/permissionHelpers.test.ts: update the assertion for the new shape.
2. Read-only message
src/generic/messages.ts: addreadOnlyTooltipwith the exact copy above
(description included for translators). Shared so both the review tab and the
preview modal use the same string.
3. Page gating + read-only propagation
src/course-libraries/CourseLibraries.tsx:- gate on
canViewLibraryUpdates(PermissionDeniedAlert otherwise); - compute
readOnly = !canManageLibraryUpdates; - pass
readOnlytoReviewTabContent.
- gate on
src/header/hooks.tsx: show the "Libraries" content-menu link based on
canViewLibraryUpdatesinstead ofcanManageLibraryUpdates.
4. Review tab card actions
src/course-libraries/ReviewTabContent.tsx:- thread
readOnlythroughReviewTabContent→ItemReviewList; - disable "Update" (
LoadingButton) and "Ignore" buttons when read-only; - wrap the disabled buttons in
OverlayTrigger/Tooltip(via a<span>, the
established pattern fromsrc/course-unit/add-component/add-component-btn); - keep "Review Updates" enabled;
- pass
readOnlyinto the preview modal.
- thread
5. Preview modal
src/course-unit/preview-changes/index.tsx:- add optional
readOnlyprop (defaultfalse) so existing callers
(OutlineNode.tsx,LibraryReferenceCard.tsx, iframe wrapper) are unaffected; - disable + tooltip on "Accept changes"/"Ignore changes" and the locally
modified variants "Update to published library content"/"Keep course content".
- add optional
6. Tests
src/course-libraries/CourseLibraries.test.tsx:- default permission mock includes
canViewLibraryUpdates: true; - permission-denied test now keys off
canViewLibraryUpdates: false; - new tests: read-only user sees disabled Update/Ignore with tooltip on hover;
preview modal buttons disabled with tooltip for read-only user.
- default permission mock includes
src/course-unit/preview-changes/index.test.tsx: render modal directly with
readOnlyand assert disabled buttons + tooltip.src/header/hooks.test.tsx: mocks switched tocanViewLibraryUpdates.
Reacted by Bryann Valderrama- A user with
I want to verify one last thing here and that is the out of sync Alert that is displayed in the course outline and libraries updates. There is not indication of what to do with it for Course Auditor in the Figma, and keep it does not cause any harm because it redirects to Library Updates page. However, I feel the message misleading for that specific role because it says "Review updates to accept or ignore changes" -> Action that cannot perform
I wonder if we would like to keep it as it is, or we should either hide the Alert or remove the review part of message for read only permissions.
Reacted by Bryann Valderrama@dcoa Do we use that message somewhere else? If not, I think we can change the last sentence to 'Review updates to see what changed' and it may be less misleading.
Reacted by Diana Olarte
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsBlocked
Description
This task focuses exclusively on the views and components related to Library Updates within the Authoring MFE. The goal is to ensure that users with these roles interact only with the permitted elements, by applying “read-only” states for Course Auditors and enabling full management actions for Course Editors, as defined by the permission matrix.
Permission Matrix
courses.manage_library_updatescourses.view_library_updatesApproved Design: Figma