Skip to content

Permitted roles for restricted pages - #4112

Open
sascha-karnatz wants to merge 6 commits into
mainfrom
permitted-roles-for-restricted-pages
Open

Permitted roles for restricted pages#4112
sascha-karnatz wants to merge 6 commits into
mainfrom
permitted-roles-for-restricted-pages

Conversation

@sascha-karnatz

@sascha-karnatz sascha-karnatz commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Note

There was a previous PR #4102 that used restricted_roles instead of permitted_roles as column.

What is this pull request for?

Add a permitted_roles column to the Page model to extend the restricted page behavior. This way it is possible restrict the access to pages only for a smaller set of users with a given role.

Notable changes (remove if none)

There is an addition to the MemberUser permission that is now evaluating also the permitted_roles column on the page. The default value is "member" and it should behave same way as before.

Screenshots

CleanShot 2026-07-29 at 11 52 13@2x

Checklist

  • I have followed Pull Request guidelines
  • I have added a detailed description into each commit message
  • I have added tests to cover this change

@codecov

codecov Bot commented Jul 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.27%. Comparing base (08d3b42) to head (89fe4b0).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4112   +/-   ##
=======================================
  Coverage   98.26%   98.27%           
=======================================
  Files         350      351    +1     
  Lines        9184     9204   +20     
=======================================
+ Hits         9025     9045   +20     
  Misses        159      159           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tvdeyen tvdeyen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a nice feature.

Comment thread config/alchemy/config.yml Outdated
Comment thread spec/dummy/config/initializers/alchemy.rb Outdated
# Accepts an array of role names (as sent by the admin form) or a raw string.
#
def permitted_roles=(roles)
self[:permitted_roles] = roles.is_a?(Array) ? roles.select(&:present?).join(" ") : roles

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can we add a validation that if there is no permitted role it fails? so we never end up with an unreachable page?

Comment thread app/models/alchemy/page.rb
* <input type="text" name="page[foo]">
* </alchemy-conditional-field>
*/
class ConditionalField extends HTMLElement {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is very helpful, can we extract that into a separate PR and use it for the publication fields as well?

Comment thread app/components/alchemy/admin/page_permitted_roles_select.rb Outdated
@tvdeyen tvdeyen added the enhancement New feature or enhancement label Jul 29, 2026
@tvdeyen tvdeyen added this to the 8.4 milestone Jul 29, 2026
Add a new permitted_roles column with a space separated list of roles, that can access a page. The default values is "member" to support the same behavior as before.
...to test that feature better in the dummy app.
Add getter and setter to the page model to split and join the group collection. Extend the set_restrictions_to_child_pages behavior to update permitted_roles as well. It was necessary to move from before_save to after_save to update restricted and permitted_roles of child pages. Otherwise inherit_restricted_status would read old data from the database.
Test if the user has the correct role to read the page. This change only affects the MemberUser permission. GuestUser can't see restricted pages and AuthorUser includes the MemberUser module. If Alchemy will be extended by other roles (like restricted_test in the Dummy app), it is necessary to create new abilities to prevent misconfigurations (like to many redirects).
This small web component allow to toggle inputs in forms based on checkbox values. The idea is to show the permitted_roles select only, if the user enabled the restricted checkbox before.
Provide a new PagePermittedRolesSelect view component to render a select with all configured permitted_roles. The select is only visible if the restricted checkbox is enabled.
@sascha-karnatz
sascha-karnatz force-pushed the permitted-roles-for-restricted-pages branch from f87322a to 89fe4b0 Compare July 30, 2026 07:49
sascha-karnatz added a commit to AlchemyCMS/alchemy_i18n that referenced this pull request Jul 30, 2026
These translations all translated by Claude Opus 5.

Ref: AlchemyCMS/alchemy_cms#4112
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants