Implement read-only access to workspace pages#91305
Conversation
|
Hey, I noticed you changed If you want to automatically generate translations for other locales, an Expensify employee will have to:
Alternatively, if you are an external contributor, you can run the translation script locally with your own OpenAI API key. To learn more, try running: npx ts-node ./scripts/generateTranslations.ts --helpTypically, you'd want to translate only what you changed by running |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bddbc9abf
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
🦜 Polyglot Parrot! 🦜Squawk! Looks like you added some shiny new English strings. Allow me to parrot them back to you in other tongues: View the translation diffdiff --git a/src/languages/de.ts b/src/languages/de.ts
index 76dc95de..caa2c01d 100644
--- a/src/languages/de.ts
+++ b/src/languages/de.ts
@@ -4379,6 +4379,8 @@ ${amount} für ${merchant} – ${date}`,
cardAdminAlternateText: 'Arbeitsbereichskarten verwalten.',
peopleAdminAlternateText: 'Mitglieder und Genehmigungsabläufe verwalten.',
paymentsAdminAlternateText: 'Workflow-Zahlungen verwalten.',
+ readOnlyActionTitle: 'Nur langsam …',
+ readOnlyActionPrompt: 'Ihre Workspace-Rolle kann diese Einstellungen anzeigen, aber nicht bearbeiten.',
},
createdForClient: {
title: 'Du hast einen Workspace für deinen Kunden erstellt!',
diff --git a/src/languages/es.ts b/src/languages/es.ts
index 2def7ad2..e43a7c76 100644
--- a/src/languages/es.ts
+++ b/src/languages/es.ts
@@ -4163,7 +4163,7 @@ ${amount} para ${merchant} - ${date}`,
memberNotFound: 'Miembro no encontrado. Para invitar a un nuevo miembro al espacio de trabajo, por favor, utiliza el botón invitar que está arriba.',
notAuthorized: `No tienes acceso a esta página. Si estás intentando unirte a este espacio de trabajo, pide al dueño del espacio de trabajo que te añada como miembro. ¿Necesitas algo más? Comunícate con ${CONST.EMAIL.CONCIERGE}`,
readOnlyActionTitle: 'No tan rápido...',
- readOnlyActionPrompt: 'Tu rol en el espacio de trabajo puede ver esta configuración, pero no editarla.',
+ readOnlyActionPrompt: 'Tu rol en el espacio de trabajo puede ver estos ajustes, pero no puede editarlos.',
goToWorkspace: 'Ir al espacio de trabajo',
duplicateWorkspace: 'Duplicar espacio de trabajo',
duplicateWorkspacePrefix: 'Duplicar',
diff --git a/src/languages/fr.ts b/src/languages/fr.ts
index 4a1b55c5..fbab1f2e 100644
--- a/src/languages/fr.ts
+++ b/src/languages/fr.ts
@@ -4388,6 +4388,8 @@ ${amount} pour ${merchant} - ${date}`,
cardAdminAlternateText: 'Gérer les cartes de l’espace de travail.',
peopleAdminAlternateText: 'Gérez les membres et les workflows d’approbation.',
paymentsAdminAlternateText: 'Gérer les paiements de workflow.',
+ readOnlyActionTitle: 'Pas si vite...',
+ readOnlyActionPrompt: "Votre rôle dans l'espace de travail peut afficher ces paramètres, mais ne peut pas les modifier.",
},
createdForClient: {
title: 'Vous avez créé un espace de travail pour votre client !',
diff --git a/src/languages/it.ts b/src/languages/it.ts
index 9cbca2c1..37355081 100644
--- a/src/languages/it.ts
+++ b/src/languages/it.ts
@@ -4365,6 +4365,8 @@ ${amount} per ${merchant} - ${date}`,
cardAdminAlternateText: 'Gestisci le carte dello spazio di lavoro.',
peopleAdminAlternateText: 'Gestisci i membri e i flussi di approvazione.',
paymentsAdminAlternateText: 'Gestisci i pagamenti del flusso di lavoro.',
+ readOnlyActionTitle: 'Non così in fretta...',
+ readOnlyActionPrompt: 'Il tuo ruolo nello spazio di lavoro può visualizzare queste impostazioni, ma non può modificarle.',
},
createdForClient: {
title: 'Hai creato uno spazio di lavoro per il tuo cliente!',
diff --git a/src/languages/ja.ts b/src/languages/ja.ts
index 7ad1002c..669c4ae6 100644
--- a/src/languages/ja.ts
+++ b/src/languages/ja.ts
@@ -4333,6 +4333,8 @@ ${integrationName === CONST.ONBOARDING_ACCOUNTING_MAPPING.other ? 'あなたの'
cardAdminAlternateText: 'ワークスペースカードを管理します。',
peopleAdminAlternateText: 'メンバーと承認ワークフローを管理します。',
paymentsAdminAlternateText: 'ワークフローの支払いを管理します。',
+ readOnlyActionTitle: 'ちょっと待ってください…',
+ readOnlyActionPrompt: 'このワークスペースでの現在のロールでは、これらの設定を表示できますが、編集することはできません。',
},
createdForClient: {
title: 'クライアントのワークスペースを作成しました!',
diff --git a/src/languages/nl.ts b/src/languages/nl.ts
index 226b9669..1eee4d29 100644
--- a/src/languages/nl.ts
+++ b/src/languages/nl.ts
@@ -4361,6 +4361,8 @@ ${amount} voor ${merchant} - ${date}`,
cardAdminAlternateText: 'Werkruimtekaarten beheren.',
peopleAdminAlternateText: 'Beheer leden en goedkeuringsworkflows.',
paymentsAdminAlternateText: 'Workflowsbetalingen beheren.',
+ readOnlyActionTitle: 'Zo snel niet...',
+ readOnlyActionPrompt: 'Je rol in de workspace kan deze instellingen bekijken, maar niet bewerken.',
},
createdForClient: {
title: 'Je hebt een werkruimte voor je klant aangemaakt!',
diff --git a/src/languages/pl.ts b/src/languages/pl.ts
index 4e1efe2b..a63eeb8e 100644
--- a/src/languages/pl.ts
+++ b/src/languages/pl.ts
@@ -4353,6 +4353,8 @@ ${amount} dla ${merchant} - ${date}`,
cardAdminAlternateText: 'Zarządzaj kartami przestrzeni roboczej.',
peopleAdminAlternateText: 'Zarządzaj członkami i procesami akceptacji.',
paymentsAdminAlternateText: 'Zarządzaj płatnościami w przepływie pracy.',
+ readOnlyActionTitle: 'Nie tak szybko...',
+ readOnlyActionPrompt: 'Twoja rola w przestrzeni roboczej pozwala ci przeglądać te ustawienia, ale nie możesz ich edytować.',
},
createdForClient: {
title: 'Utworzyłeś przestrzeń roboczą dla swojego klienta!',
diff --git a/src/languages/pt-BR.ts b/src/languages/pt-BR.ts
index cf3bef38..5c98c2f9 100644
--- a/src/languages/pt-BR.ts
+++ b/src/languages/pt-BR.ts
@@ -4355,6 +4355,8 @@ ${amount} para ${merchant} - ${date}`,
cardAdminAlternateText: 'Gerenciar cartões do workspace.',
peopleAdminAlternateText: 'Gerencie membros e fluxos de aprovação.',
paymentsAdminAlternateText: 'Gerencie pagamentos de fluxo de trabalho.',
+ readOnlyActionTitle: 'Calma lá...',
+ readOnlyActionPrompt: 'Seu papel no workspace pode ver estas configurações, mas não pode editá-las.',
},
createdForClient: {
title: 'Você criou um espaço de trabalho para seu cliente!',
diff --git a/src/languages/zh-hans.ts b/src/languages/zh-hans.ts
index d35db883..ad3b857b 100644
--- a/src/languages/zh-hans.ts
+++ b/src/languages/zh-hans.ts
@@ -4257,6 +4257,8 @@ ${amount},商户:${merchant} - 日期:${date}`,
cardAdminAlternateText: '管理工作区卡片。',
peopleAdminAlternateText: '管理成员和审批流程。',
paymentsAdminAlternateText: '管理工作流付款。',
+ readOnlyActionTitle: '别急……',
+ readOnlyActionPrompt: '你的工作区角色可以查看这些设置,但不能编辑。',
},
createdForClient: {
title: '您已为客户创建了工作区!',
Note You can apply these changes to your branch by copying the patch to your clipboard, then running |
|
@JmillsExpensify please review the product video under |
Reviewer Checklist
Screenshots/VideosAndroid: HybridAppAndroid: mWeb ChromeiOS: HybridAppiOS: mWeb SafariMacOS: Chrome / Safari |
JmillsExpensify
left a comment
There was a problem hiding this comment.
This looks really solid to me!
|
Added Design to the PR so that we can get their take as well. |
|
Looks solid so far. I do think we need to make a final decision on our approach here though. Are we leaning towards always showing buttons, but making them disabled and then using the centered alert modal? |
|
Yeah, that's true that where we land for the HR integrations could change this one too. I tend to think that we do that separately and not block this PR on that consideration. |
|
Yeah I'm down to not block this PR and follow up if needed. This is looking good so far! I think I caught a few examples in the video above: any non-editable push rows should not have any hover states. Also, for some of these table items, I think the Auditor will need to be able to click on them to see the (read-only) details RHP, right? |
Pujan92
left a comment
There was a problem hiding this comment.
Some initial review comments
| const shouldShowProtectedItems = | ||
| canWriteWorkspaceSettings || | ||
| [ |
There was a problem hiding this comment.
| const shouldShowProtectedItems = | |
| canWriteWorkspaceSettings || | |
| [ | |
| const shouldShowProtectedItems = | |
| [ |
We can remove canWriteWorkspaceSettings now as canReadPolicyFeature will be enough
| } | ||
|
|
||
| // We check isPendingDelete and prevIsPendingDelete to prevent the NotFound view from showing right after we delete the workspace | ||
| const canShowPage = hasAccessToPolicyFeature ?? (canEditWorkspaceSettings(policy, currentUserLogin) || shouldShowNonAdmin); |
There was a problem hiding this comment.
| const canShowPage = hasAccessToPolicyFeature; |
We can also get rid of the prop shouldShowNonAdmin, maybe in future pr if not now
| onPress={canWriteReportFields ? () => Navigation.navigate(ROUTES.REPORTS_DEFAULT_TITLE.getRoute(policyID)) : undefined} | ||
| interactive={canWriteReportFields} |
There was a problem hiding this comment.
| onPress={canWriteReportFields ? () => Navigation.navigate(ROUTES.REPORTS_DEFAULT_TITLE.getRoute(policyID)) : undefined} | |
| interactive={canWriteReportFields} | |
| onPress={() => Navigation.navigate(ROUTES.REPORTS_DEFAULT_TITLE.getRoute(policyID))} | |
| interactive={canWriteReportFields} |
Setting interactive is enough to call/reject onPress event
| if (!canWriteReportFields) { | ||
| showReadOnlyModal(); | ||
| return; | ||
| } | ||
|
|
There was a problem hiding this comment.
| if (!canWriteReportFields) { | |
| showReadOnlyModal(); | |
| return; | |
| } |
Do we really need this block as we already have disabled and disabledAction prop set?
| ? () => { | ||
| Navigation.navigate(ROUTES.POLICY_ACCOUNTING_NETSUITE_SUBSIDIARY_SELECTOR.getRoute(policyID)); | ||
| } | ||
| : undefined, |
There was a problem hiding this comment.
Let's add an interactive prop to avoid hover effect
interactive: canWriteAccounting,
Explanation of Change
This adds the frontend support for workspace scoped roles.
Auditors can now open workspace pages they have read access to, including direct links. The workspace menu checks feature read permissions before showing each item. Page access wrappers use the new policy feature read check instead of requiring full admin access when a page passes
policyFeature.This also allows read-only access by disabling or hiding write-only controls on the More Features, Expensify Card, and Company Cards top-level pages.
Fixed Issues
$ #90497, #90498
PROPOSAL:
Tests
Offline tests
QA Steps
Same as tests.
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari
Screen.Recording.2026-05-22.at.1.28.50.AM.mov