1.5 KiB
1.5 KiB
V13-FE-024 — Permission route metadata slice note
- Requirement: REQ-FE-AUTHZ
- API/UI/Test: UI-AUTH-01 / T-FE-AUTH-01
- Source: v60 fail-closed permission boundary; current
frontend/src/features/{models,shadow-run}/registry.tsdeclarations. - Assumption:
model.readis the only permission identifier currently evidenced by the active feature registries. - Unknown: Authenticated permission hydration and the complete route-to-permission catalog are not yet connected to the active router.
- Decision Required: Security/FE owners must approve the auth permission source and route visibility behavior before enabling a global navigation guard.
Applied boundary
- Added
permissions: ['model.read']to the four active ModelOps routes whose feature registries already declare that permission. - Added a pure
canAccessRoutepolicy that fails closed for declared permissions and does not perform authentication or network access. - Kept API authorization as the final authority; this Slice does not claim server security or hide routes globally.
- Did not invent permissions for financial, operations, internal, or portfolio routes.
Evidence
pnpm test -- src/shared/auth/tests/routeAccess.spec.ts
PASS: 1 file / 3 tests (2026-08-12)
The third test verifies all four active ModelOps route permissions match their feature registries.
pnpm typecheck
PASS (2026-08-12)
Status remains IN_PROGRESS until the permission source and global route policy are approved.