Skip to content

Investigate and validate current Instructor Dashboard tabs, endpoints and permissions #505

Description

@BryanttV

Description

Before deepening the granular-permissions work, we need an accurate, up-to-date inventory of every Instructor Dashboard tab (both the ones in scope for this epic and the ones listed as out of scope), the endpoint(s) each tab depends on, and how access to each of them is currently decided.

This isn't just about the legacy role checks (staff, instructor, data_researcher, forum_admin, admin…). Several tabs are also gated by settings, waffle flags/switches, content_groups, or additional services that aren't obvious from the role alone (e.g. is_bulk_email_feature_enabled, certs_instructor_enabled, can_see_special_exams). We need both layers documented so we know exactly what's on by default for a given role, and what only becomes visible/available when something extra is configured or enabled.

The output of this investigation feeds directly into the Permission catalog and the Appendix: out-of-scope tab inventory tables already in this epic — it should validate what's there, correct anything stale, and fill the gaps (especially for the out-of-scope tabs, where "what's missing" is currently a placeholder).

Scope

  • Enumerate every tab currently rendered by the Instructor Dashboard (MFE), in scope and out of scope for this epic.
  • For each tab, identify the backend endpoint(s) it calls (instructor v2 API, v1 API, and any other app it depends on, e.g. course_groups for Cohorts).
  • For each endpoint, document the current access control logic as implemented today:
    • Which legacy role(s) are checked by default (staff, instructor, data_researcher, forum_admin, admin, etc.).
    • Whether access additionally depends on a setting, waffle flag/switch, course advanced setting, content_groups configuration, or an optional/paid service (e.g. proctoring, bulk email, certificates generation).
    • Where in the code that check lives (view, serializer, decorator).
  • Cross-check the findings against:
    • The existing Permission catalog table in this epic (confirm scope/description still match reality).
    • The existing Appendix: out-of-scope tab inventory table (confirm current access control and flag known gaps precisely, instead of "TBD").
  • Flag any tab/endpoint that isn't currently covered by either table.
  • Note any tab/endpoint whose visibility depends on configuration that a fresh sandbox doesn't have by default (relevant context for [Issue 5.1], which enables tabs by default in the sandbox).

Acceptance criteria

  • All Instructor Dashboard tabs (in scope and out of scope) are inventoried with their endpoint(s).
  • For each tab/endpoint, the current access control logic is documented, distinguishing default role-only access from access that also requires a setting, flag, or additional service, with the exact flag/setting name.
  • The Permission catalog table and the Appendix table in this epic are reviewed against the findings, and discrepancies are called out (or a follow-up PR updates them directly).
  • Any tab/endpoint not currently reflected in either table is explicitly flagged for follow-up.
  • Findings are shared with the team (e.g. as a comment/doc on this issue) to inform open question 1 (permission split between Course Admin and Course Staff) and the out-of-scope epic planning.

Dependencies

  • Blocked by: none — can start any time.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

willowReleased in Willow

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions