Skip to content

feat(core): dynamic menu providers and runtime permission sources (#340, #334) - #407

Open
antosubash wants to merge 2 commits into
mainfrom
feat/340-334-runtime-menus-and-permissions
Open

antosubash wants to merge 2 commits into
mainfrom
feat/340-334-runtime-menus-and-permissions

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Fixes #340
Fixes #334

Design

Menu providers (#340). MenuRegistry.add_provider(fn) takes fn(request) returning an iterable of MenuItem; sync or async. InertiaLayoutDataMiddleware now calls the new async get_for_request, which collects provider items per request (after auth and request.state.tenant_id are resolved) and passes them to the unchanged get_for_user as extra_items, so role/permission filtering, translation, ordering and grouping are shared with static items. The static sorted cache is untouched. A provider that raises is logged and contributes nothing. MenuRegistry.remove(predicate) drops static items and invalidates the cache.

Permission sources (#334). PermissionRegistry.add_source(name, provider) with a sync provider returning keys or (key, label) pairs; output is cached per source and refreshed by invalidate_source(name). all_permissions, groups, has and therefore role_map wildcard expansion, admin's implicit all-permissions, the role editor and both RequiresPermission variants see source permissions, with no changes needed outside the registry. Source permissions are persisted like any key. A failing source is logged and contributes nothing. The role editor API gains an additive PermissionGroupOut.labels.

Additive only, to limit conflicts with #398 / #404.

Not done: label translation keys for source permissions (labels are literal; t() needs literal keys in TSX), and no frontend rendering of labels yet.

https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4

MenuRegistry.add_provider / remove; PermissionRegistry.add_source /
invalidate_source, surfaced in all_permissions, groups and the role editor.

Claude-Session: https://claude.ai/code/session_01M9neheZZEe3sVpDi2S3zT4
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-05T11:33:20.017757Z 7c29c8c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: d288750
Status: ✅  Deploy successful!
Preview URL: https://f3960f28.simple-module-python.pages.dev
Branch Preview URL: https://feat-340-334-runtime-menus-a.simple-module-python.pages.dev

View logs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant