bcgov / bcgov/bcbox

The Top Delete Button Does Not Check Permissions

Open
#128 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Vue
Stars
11
Forks
3
PR merge metrics
No merged PRs in 30d

Description

#### Describe the bug
On the Files page, the top delete button does not check to see if the user has the required permissions to delete the file before sending the call to COMS. This generates confusing messages to the user -- both an error and a successful delete message are shown.

#### To Reproduce

Steps to reproduce the behavior:

1. Have READ only permissions granted on a file or bucket to you
2. Select the checkbox to the left of the file
3. Use the delete button at the top of the screen
4. See error and success messages
![image](https://github.com/bcgov/bcbox/assets/6244673/fbd682a0-d298-4255-bec1-cc59c4114d09)

#### Expected behavior
After clicking the delete button, BCBox should check the user's permissions and if they don't have them should generate a message to the user alerting them. BCBox should only send a delete request to COMS if the user has the required permissions.

#### Desktop (please complete the following information):

- OS: Windows 10
- Browser: Edge
- Version: 117.0.2045.31

Contributor guide

Open the contributing guide

Research direction

Start at the Files page's top delete-button flow and reproduce the problem with READ-only access to a file or bucket. Trace the permission check and COMS request; done means unauthorized users receive an alert, no delete request is sent, and conflicting error and success messages no longer appear.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, typescript
Domain
authorization, frontend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.