Skip to content

feat(dashboard): platform-only stats behind dashboard.view (#374) [stack 3/11] - #387

Merged
antosubash merged 7 commits into
tenancy/02-permissionsfrom
tenancy/03-dashboard
Oct 1, 2026
Merged

antosubash merged 7 commits into
tenancy/02-permissionsfrom
tenancy/03-dashboard

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #374. Stack 3/11 of the tenancy-adoption series (base: #386).

What

/api/dashboard/stats had no permission guard, so any tenant member could see platform-wide user counts and health. Dashboard stats are now platform-only:

  • A new dashboard.view permission. Admin holds it through *, and no tenant role is mapped to it.
  • RequiresPermission("dashboard.view") on the stats API.
  • /dashboard/ is still everyone's post-login landing page. Viewers without the permission get can_view_stats=false and a welcome card (Home.tsx), and no stats props are sent to them.
  • The 30-second global cache is unchanged: User is not tenant-scoped, and the cache never opens the API to anyone without the permission (tested).

⚠️ Behaviour change

Non-admin platform users (the plain user role) no longer see the stats until an admin grants dashboard.view in the role editor.

Tests

  • 7 new tests in test_dashboard_permission.py.
  • make test-py: 3342 passed.
  • make lint is clean.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: 103b976
Status: ✅  Deploy successful!
Preview URL: https://a2556886.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-03-dashboard.simple-module-python.pages.dev

View logs

…ls (review of #374)

Gating the stats on dashboard.view took them away from every non-admin on
every install. With multi_tenant off the install is the only tenant, so the
module now maps dashboard.view onto the platform user role at startup. With
multi_tenant on it stays unmapped: every tenant member holds user.

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:15
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:19:32.272922Z 103b976 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 0516a7d into main Oct 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dashboard: platform-wide stats cache and unscoped User counts need a tenant decision

1 participant