Skip to content

feat(console): make delegated_admin reachable and narrow both role pickers (framework#3697) - #2891

Merged
os-zhuang merged 1 commit into
mainfrom
claude/console-delegated-admin-role
Jul 28, 2026
Merged

feat(console): make delegated_admin reachable and narrow both role pickers (framework#3697)#2891
os-zhuang merged 1 commit into
mainfrom
claude/console-delegated-admin-role

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Follow-on to objectstack-ai/objectstack#3722 (merged), which registered a fourth organization role. Companion to #2868, which shipped the placement half of this UX.

The gap

objectstack-ai/objectstack#3722 gave ADR-0105 D8's scope-bounded issuance gate its missing caller: delegated_admin, the membership grade that may reach /organization/invite-member without being an org admin. #2868 already narrows the unit/position pickers with describeDelegableScope().

But the console couldn't select the role in the first place — MembersPage.tsx and InviteMemberDialog.tsx each inlined:

type Role = 'owner' | 'admin' | 'member';

So the capability the framework grew was unreachable from either screen. Provisioning a delegate today requires a raw API call — I had to curl /organization/update-member-role to browser-verify the framework side at all.

One vocabulary, not two

Role names, labels and narrowing rules move into @object-ui/auth's new org-roles module (ORG_ROLES, ORG_ROLE_LABELS, orgRoleGrade, invitableOrgRoles, assignableOrgRoles); both screens consume it.

Honest caveat, stated in the module itself: this list still mirrors the server rather than deriving from it. /auth/config publishes feature flags but no role vocabulary, so there is no surface to read — objectstack-ai/objectstack#3723 tracks making one list the source for all of them (the framework already carries the same list twice: the better-auth roles map and two enforced Field.select option sets; this is the third). Until that lands, a server-side role addition means one console edit instead of two.

Both pickers now narrow — mirroring different server gates

Same property #2868 established for placement: narrows, does not decide. The server re-checks; the only failure the console can cause is proposing something that then 403s.

Picker Mirrors Rule
Invite role framework's beforeCreateInvitation role cap Never above the issuer's own grade; a below-admin issuer may invite as member only
Change role better-auth's update-member-role route Needs member:["update"] (owner/admin only — delegated_admin is built from memberAc and holds member: []); only an owner may set owner or re-role an existing owner

Concretely: a delegated_admin who picked "Admin" was heading for a 403 from the framework's role cap — that option is simply no longer offered. An actor who may re-role nobody now gets no menu items instead of three that would fail.

Fails toward less: an unresolved membership offers member alone on invite, and nothing on re-role. An ordinary invitation's request body is byte-identical to before.

Changes

File What
packages/auth/src/org-roles.ts New. The vocabulary + both narrowing helpers, with the mirror-not-derive caveat and the #3723 pointer
packages/auth/src/index.ts Exports them
.../manage/InviteMemberDialog.tsx Role select driven by invitableOrgRoles(activeMember?.role)
.../manage/MembersPage.tsx Change-role menu driven by assignableOrgRoles(activeMember?.role, member.role)
.../__tests__/InviteMemberDialog.placement.test.tsx Its wholesale @object-ui/auth mock now spreads importActual, so the helpers under test are the real ones rather than mocked away

Verification

  • packages/auth/src/__tests__/org-roles.test.ts — grade ladder, both narrowing rules, and the fail-closed floor for each.
  • packages/app-shell/.../InviteMemberDialog.roleCap.test.tsx — owner sees all four; admin gets the delegate grade but not owner; a delegate sees member only (the escalation chain has no UI entry); an unloaded membership still allows the ordinary invite; the narrowed default still submits an unchanged payload.
  • Full suite: 654 files, 7684 tests passing, 24 skipped.
  • turbo lint on both packages: 0 errors (warnings are the repo's pre-existing baseline). turbo build (tsc): 29/29 successful.

Note for translators

organization.roles.* has never been defined in any locale bundle — all four labels (owner/admin/member included) resolve through their defaultValue English fallback. The new role follows the same pattern rather than becoming the only localized one. Localizing the set is a separate, deliberate change.


Generated by Claude Code

…pickers (framework#3697)

The framework registered a fourth organization role — `delegated_admin`, the
grade that may reach `/organization/invite-member` WITHOUT being an org admin,
which is what finally gives ADR-0105 D8's scope-bounded issuance gate a caller.
#2868 already shipped the placement half of this UX, but the console could not
select the role at all: `MembersPage` and `InviteMemberDialog` each inlined
`type Role = 'owner' | 'admin' | 'member'`, so the capability the framework grew
was unreachable from either screen.

One vocabulary, not two. Role names, labels and narrowing rules now live in
`@object-ui/auth`'s new `org-roles` module and both screens consume it. The list
still MIRRORS the server rather than deriving from it — `/auth/config` publishes
feature flags but no role vocabulary — so the module says so and points at
objectstack-ai/objectstack#3723, which tracks making one list the source for all
of them.

Both pickers now narrow to what the server will accept, the way the placement
picker already does. They mirror DIFFERENT gates:

- invite role  ← `beforeCreateInvitation`'s role cap: never above the issuer's
  own grade; a below-admin issuer may invite as `member` only. A
  `delegated_admin` picking "Admin" would have 403'd; it is no longer offered.
- change role  ← better-auth's `update-member-role`: needs `member:["update"]`
  (owner/admin only), and only an owner may set `owner` or re-role an existing
  owner. An actor who may re-role nobody gets no items rather than three that
  would 403.

Narrowing is convenience, not the boundary — the server re-checks — and it fails
toward less: an unresolved membership offers `member` alone on invite, nothing
on re-role. An ordinary invitation's request body is byte-identical to before.

The existing placement test mocked `@object-ui/auth` wholesale; it now spreads
`importActual` so the narrowing helpers under test are the real ones.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015s4qPrCKBvVwmFeSsFHgNp
@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 28, 2026 2:42am

Request Review

@github-actions github-actions Bot added the tests label Jul 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-DSNh5EGj.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.17KB 0.96KB
auth (org-roles.js) 5.50KB 2.36KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 449.81KB 97.81KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.78KB 32.15KB
fields (index.js) 218.37KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 55.86KB 15.77KB
plugin-chatbot (index.js) 179.53KB 42.79KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 214.86KB 52.39KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.47KB 25.10KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 177.88KB 46.63KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.48KB 23.23KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.67KB 20.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants