Skip to content

Commit 45565a0

Browse files
committed
docs: revise admin UX spec for post-merge state
- Note Permissions module (#37) as separate concern; add cross-link from detail page - Reference PERM_USERS_MANAGE constant convention (#34) - Confirm UserService stays concrete (Protocol drop #39 didn't touch it)
1 parent b922870 commit 45565a0

1 file changed

Lines changed: 14 additions & 1 deletion

File tree

‎docs/superpowers/specs/2026-04-17-users-admin-ux-design.md‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,20 @@
11
# Users Module — Admin UX (Sub-project 2 of 4)
22

3-
**Date:** 2026-04-17
3+
**Date:** 2026-04-17 (revised 2026-04-20 after origin/main sync)
44
**Status:** Design draft.
55
**Scope:** Make the admin list and detail pages useful for managing many users.
66

77
Second of four sub-projects. Sub-project 1 (quality pass) has shipped; this builds on a clean `UserService` / `api_admin.py` split. Sub-projects 3 (self-service) and 4 (security) come after.
88

9+
## Post-merge context (2026-04-20)
10+
11+
Origin/main added four modules and one refactor that shape this spec:
12+
13+
- **Permissions module (#37)** — separate module at `/permissions` with its own admin UI. Manages role→permission-key assignments and direct per-user permission grants (`UserEdit` page at `/permissions/users/{user_id}`). **Does not overlap with this spec** — roles on the users edit page are still role *membership*, not permission keys. **Add a cross-link** from the users detail page ("Manage permissions →") so admins can jump between the two.
14+
- **Constants convention (#34)** — permission strings are now module-level constants (`PERM_USERS_MANAGE`). New code here uses those constants, not literals.
15+
- **Protocol drop (#39)** — `IProductService`, `IPermissionService`, `IBackgroundTaskService`, `ISettingService` deleted. `UserService` was never in a Protocol and stays a concrete class; new admin-facing code type-hints against `UserService` directly.
16+
- **Settings, BackgroundTasks, FileStorage modules (#38, #36, #35)** — independent; no impact on this spec.
17+
918
## Goal
1019

1120
Extend admin pages with filtering, sorting, confirmation prompts for destructive actions, and a richer detail page. Keep public-contract changes additive: existing requests continue to return the same shapes.
@@ -83,6 +92,8 @@ Metadata
8392

8493
**No "mark unverified" action** — that's a foot-gun with no clear use case; revisit if someone asks.
8594

95+
**Cross-link to Permissions module.** Below the Roles card, add a single link: `Manage permissions →` pointing at `/permissions/users/{user.id}`. Rendered only if the Permissions module is installed (detected via a prop passed from the view — e.g. `has_permissions_module: bool` computed from the app's module registry). Keeps the users module decoupled from the permissions one: users doesn't import from permissions, the view just checks module presence.
96+
8697
## Out of contract-change scope
8798

8899
- HTTP status codes and response shapes for existing endpoints are preserved.
@@ -159,6 +170,7 @@ Each step is independently shippable. `make test` and `make lint` green between.
159170
6. **Frontend detail-page Metadata card.**
160171
- 6a: Render Metadata card with `created_at`, `last_login_at`, `disabled_at`, verified state.
161172
- 6b: Add [Mark verified] button wired to the new endpoint.
173+
- 6c: Render cross-link to `/permissions/users/{id}` when the Permissions module is installed (view-side flag).
162174

163175
## Risks
164176

@@ -175,3 +187,4 @@ Each step is independently shippable. `make test` and `make lint` green between.
175187
- `UserListItem` gains `created_at`; no other schema changes.
176188
- New `PATCH /admin/{id}/verify` endpoint exists, idempotent, 404s on unknown UUID.
177189
- Disable + reset-link actions require confirmation on the admin detail page.
190+
- Detail page shows a "Manage permissions →" link to the Permissions module when installed; hidden otherwise.

0 commit comments

Comments
 (0)