Description
Before deepening the granular-permissions work, we need an accurate, up-to-date inventory of every Instructor Dashboard tab (both the ones in scope for this epic and the ones listed as out of scope), the endpoint(s) each tab depends on, and how access to each of them is currently decided.
This isn't just about the legacy role checks (staff, instructor, data_researcher, forum_admin, admin…). Several tabs are also gated by settings, waffle flags/switches, content_groups, or additional services that aren't obvious from the role alone (e.g. is_bulk_email_feature_enabled, certs_instructor_enabled, can_see_special_exams). We need both layers documented so we know exactly what's on by default for a given role, and what only becomes visible/available when something extra is configured or enabled.
The output of this investigation feeds directly into the Permission catalog and the Appendix: out-of-scope tab inventory tables already in this epic — it should validate what's there, correct anything stale, and fill the gaps (especially for the out-of-scope tabs, where "what's missing" is currently a placeholder).
Scope
- Enumerate every tab currently rendered by the Instructor Dashboard (MFE), in scope and out of scope for this epic.
- For each tab, identify the backend endpoint(s) it calls (instructor v2 API, v1 API, and any other app it depends on, e.g.
course_groups for Cohorts).
- For each endpoint, document the current access control logic as implemented today:
- Which legacy role(s) are checked by default (
staff, instructor, data_researcher, forum_admin, admin, etc.).
- Whether access additionally depends on a setting, waffle flag/switch, course advanced setting,
content_groups configuration, or an optional/paid service (e.g. proctoring, bulk email, certificates generation).
- Where in the code that check lives (view, serializer, decorator).
- Cross-check the findings against:
- The existing Permission catalog table in this epic (confirm scope/description still match reality).
- The existing Appendix: out-of-scope tab inventory table (confirm current access control and flag known gaps precisely, instead of "TBD").
- Flag any tab/endpoint that isn't currently covered by either table.
- Note any tab/endpoint whose visibility depends on configuration that a fresh sandbox doesn't have by default (relevant context for [Issue 5.1], which enables tabs by default in the sandbox).
Acceptance criteria
Dependencies
- Blocked by: none — can start any time.
Description
Before deepening the granular-permissions work, we need an accurate, up-to-date inventory of every Instructor Dashboard tab (both the ones in scope for this epic and the ones listed as out of scope), the endpoint(s) each tab depends on, and how access to each of them is currently decided.
This isn't just about the legacy role checks (
staff,instructor,data_researcher,forum_admin,admin…). Several tabs are also gated by settings, waffle flags/switches,content_groups, or additional services that aren't obvious from the role alone (e.g.is_bulk_email_feature_enabled,certs_instructor_enabled,can_see_special_exams). We need both layers documented so we know exactly what's on by default for a given role, and what only becomes visible/available when something extra is configured or enabled.The output of this investigation feeds directly into the Permission catalog and the Appendix: out-of-scope tab inventory tables already in this epic — it should validate what's there, correct anything stale, and fill the gaps (especially for the out-of-scope tabs, where "what's missing" is currently a placeholder).
Scope
course_groupsfor Cohorts).staff,instructor,data_researcher,forum_admin,admin, etc.).content_groupsconfiguration, or an optional/paid service (e.g. proctoring, bulk email, certificates generation).Acceptance criteria
Dependencies