Skip to content

[e7d5fb64] Assignment-path capability refusal (delegate, reassign, admin set) - #1124

Open
roboco-app[bot] wants to merge 2 commits into
feature/backend/2cfe2ae4--cf55f934from
feature/backend/2cfe2ae4--cf55f934--e7d5fb64
Open

roboco-app[bot] wants to merge 2 commits into
feature/backend/2cfe2ae4--cf55f934from
feature/backend/2cfe2ae4--cf55f934--e7d5fb64

Conversation

@roboco-app

@roboco-app roboco-app Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Extend the role-transition map the enforcement layer already owns (do NOT invent a parallel capability system) with a capability check invoked on every assignment path: delegate, reassign, and the admin task-set path. When a task would be assigned to an agent whose role cannot act on the status it will hold, refuse at creation time and name the missing capability in the refusal reason (use the existing not_authorized error category with a capability-naming message — the intake leaves this choice to the cell). This covers the 54e30535 wedge shape (task assigned to a product-owner id with no delivery verbs, nobody could act). Business logic and DB writes belong in roboco/services per the architectural standard; routes stay thin. Confirm the exact module that owns the role-transition map and extend it there.

Backend Developer 1 added 2 commits September 28, 2026 20:11
@github-actions

Copy link
Copy Markdown

Thanks for opening your first pull request on RoboCo!

Quick checklist before review (most of these are enforced by CI, but worth a glance):

  • make quality — ruff format check, ruff check, mypy, pytest (≥80% coverage), and the rest of the gate
  • Panel changes pass pnpm lint and pnpm exec tsc --noEmit (run from panel/)
  • No # noqa / # type: ignore shortcuts; pre-existing violations in touched files are fixed
  • Added an entry under ## [Unreleased] in CHANGELOG.md
  • Signed the CLA (the bot will prompt you on this PR)
  • Signed your commits — master requires verified signatures (SSH signing setup)
  • Updated any affected docs under docs/

See CONTRIBUTING.md for the full workflow and the Code of Conduct for the community standards we follow.

Welcome aboard — a maintainer will review shortly.

@github-actions github-actions Bot added documentation Docs, README, CHANGELOG, governance files area: panel Touches panel/ (Next.js control panel) area: api Touches roboco/api/ (FastAPI routes, schemas, app) area: services Touches roboco/services/ (business logic, side effects) tests Test suite changes area: gateway Touches roboco/services/gateway/ (Choreographer, verb surface) area: agents Touches agents/ (prompts, role config) labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: agents Touches agents/ (prompts, role config) area: api Touches roboco/api/ (FastAPI routes, schemas, app) area: gateway Touches roboco/services/gateway/ (Choreographer, verb surface) area: panel Touches panel/ (Next.js control panel) area: services Touches roboco/services/ (business logic, side effects) cell/backend Task owned by Backend Team documentation Docs, README, CHANGELOG, governance files tests Test suite changes to feature/backend/2cfe2ae4--cf55f934

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

0 participants