ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz
[Story]: Expanded role model (org-admin, team-admin, auditor, end-user)
- 主要語言
- Rust
- 星號
- 0
- 分支
- 1
- 平均合併
- 7 小時 7 分鐘
- 30 天內合併 PR
- 237
描述
## Summary
Define the expanded role model — org-admin, team-admin, auditor, end-user — and their permission boundaries.
## Intent / Source of truth
This is the foundational definition the rest of the epic's enforcement work builds on. Part of [Epic] RBAC beyond admin and user.
## Scope
- [ ] Role and permission-boundary definitions for all four roles
- [ ] Mapping of existing platform actions to the roles allowed to perform them
- [ ] Role-assignment API (who can grant which role to whom)
## Out of scope
- Enforcement implementation (separate story) — this story is the model/definition
## Verification
A reviewed permission matrix (role x action) exists and is used as the source of truth for the enforcement story's test suite.
## Risk assessment
A definition-only story creates exactly the #177 risk if not immediately followed by enforcement tests — track this story and a4s2 as a pair, not sequential-and-forgettable.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
貢獻指南
研究方向
Use the four roles and the scope bullets as the starting requirements; inventory existing platform actions and role-assignment rules, then produce the reviewed role × action permission matrix. Confirm it covers who can grant each role and provide it as the source of truth for the paired enforcement story, a4s2, without implementing enforcement here.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- rust
- 領域
- api, authorization, security
- Issue 類型
- 功能
- 難度
- 5/5
- 預估耗時
- 一週以上
- 活躍度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100