You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 45565a0
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/superpowers/specs/2026-04-17-users-admin-ux-design.md
+14-1Lines changed: 14 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,20 @@
1
1
# Users Module — Admin UX (Sub-project 2 of 4)
2
2
3
-
**Date:** 2026-04-17
3
+
**Date:** 2026-04-17 (revised 2026-04-20 after origin/main sync)
4
4
**Status:** Design draft.
5
5
**Scope:** Make the admin list and detail pages useful for managing many users.
6
6
7
7
Second of four sub-projects. Sub-project 1 (quality pass) has shipped; this builds on a clean `UserService` / `api_admin.py` split. Sub-projects 3 (self-service) and 4 (security) come after.
8
8
9
+
## Post-merge context (2026-04-20)
10
+
11
+
Origin/main added four modules and one refactor that shape this spec:
12
+
13
+
-**Permissions module (#37)** — separate module at `/permissions` with its own admin UI. Manages role→permission-key assignments and direct per-user permission grants (`UserEdit` page at `/permissions/users/{user_id}`). **Does not overlap with this spec** — roles on the users edit page are still role *membership*, not permission keys. **Add a cross-link** from the users detail page ("Manage permissions →") so admins can jump between the two.
14
+
-**Constants convention (#34)** — permission strings are now module-level constants (`PERM_USERS_MANAGE`). New code here uses those constants, not literals.
15
+
-**Protocol drop (#39)** — `IProductService`, `IPermissionService`, `IBackgroundTaskService`, `ISettingService` deleted. `UserService` was never in a Protocol and stays a concrete class; new admin-facing code type-hints against `UserService` directly.
16
+
-**Settings, BackgroundTasks, FileStorage modules (#38, #36, #35)** — independent; no impact on this spec.
17
+
9
18
## Goal
10
19
11
20
Extend admin pages with filtering, sorting, confirmation prompts for destructive actions, and a richer detail page. Keep public-contract changes additive: existing requests continue to return the same shapes.
@@ -83,6 +92,8 @@ Metadata
83
92
84
93
**No "mark unverified" action** — that's a foot-gun with no clear use case; revisit if someone asks.
85
94
95
+
**Cross-link to Permissions module.** Below the Roles card, add a single link: `Manage permissions →` pointing at `/permissions/users/{user.id}`. Rendered only if the Permissions module is installed (detected via a prop passed from the view — e.g. `has_permissions_module: bool` computed from the app's module registry). Keeps the users module decoupled from the permissions one: users doesn't import from permissions, the view just checks module presence.
96
+
86
97
## Out of contract-change scope
87
98
88
99
- HTTP status codes and response shapes for existing endpoints are preserved.
@@ -159,6 +170,7 @@ Each step is independently shippable. `make test` and `make lint` green between.
0 commit comments