grant xblock edit access via authz edit_course_content permission - #39050
grant xblock edit access via authz edit_course_content permission#39050jacobo-dominguez-wgu wants to merge 2 commits into
Conversation
|
Thanks for the pull request, @jacobo-dominguez-wgu! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. 🔘 Update the status of your PRYour PR is currently marked as a draft. After completing the steps above, update its status by clicking "Ready for Review", or removing "WIP" from the title, as appropriate. Where can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
Description
In Studio, the per-component "Edit" action on an XBlock card is controlled by the
can_editflag inxblock_view_handler. Previouslycan_editwas derived solely from the legacyhas_studio_write_accesscheck.Under the authz course-authoring rollout, a user can be granted
courses.edit_course_contentwithout holding legacy studio write access. Those users were incorrectly denied the "Edit" action on component cards, even though the authzpermission is meant to grant exactly that capability.
This change makes
can_editthe union of the legacy check and the authz path:The
is_authz_authoring_enabled/authz_can_edit_course_contentflags are already resolved for this request via_get_authz_permissions_flags, so no additional permission lookups are introduced. When the authz flag is off, behavior is unchanged.Supporting information
Fixes openedx/openedx-authz#418
Testing instructions
Automated:
Run the regression tests added in
TestXBlockViewHandlerHeaderActionsAuthz:They cover the component edit button on a leaf
htmlcomponent preview:edit_course_contentgranted + no legacy write access → edit button shownManual:
courses.edit_course_contentwithout legacy studio write access.Demo
User with edit_course_content permission must be able to edit course content.
Screen.Recording.2026-08-31.at.3.16.16.PM.mov
AI usage notice
Used Copilot with auto model mode (Claude) to assist on the modification and creation of unit tests.
Important
Needs to be reviewed after #39013, it contains code from that pr.