You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Several access-control inconsistencies between the UI gates and the server: a dashboard advertises pages the role can't open, and a schedule endpoint is broader than the UI implies.
Evidence
IT_SERVICE dashboard → ADMIN-only pages. The IT dashboard links to /admin/createAccount and /admin/employeeSearch, but those routes are gated ADMIN in types/permissions.ts, and IT_SERVICE does not inherit ADMIN (server/utils/permissions.ts — only ADMIN is a superset). So IT users clicking those links are bounced by middleware/01.permission.global.ts. server/api/search/employees.get.ts is also ADMIN. (Note: the dashboard-consolidation work in Consolidate the 7 role dashboards into one role-aware /dashboard #282 changes how these tiles are gated — reconcile there.)
schedule/all broader than the UI.server/api/session/schedule/all.get.ts allows [USER_SERVICE, EVALUATOR], but the calendar's "see all sessions" affordance is gated USER_SERVICE || ADMIN. An EVALUATOR could call the endpoint directly and see all sessions (not just their own). EVALUATOR is clinical/PHI-cleared so it's not a leak, but it's inconsistent with the UI intent.
Impact
P2. Dead-end nav for IT users; endpoint/UI access intent drift. Worth settling as the role model is exercised.
Part of #285 (Group D — robustness).
Problem
Several access-control inconsistencies between the UI gates and the server: a dashboard advertises pages the role can't open, and a schedule endpoint is broader than the UI implies.
Evidence
/admin/createAccountand/admin/employeeSearch, but those routes are gatedADMINintypes/permissions.ts, and IT_SERVICE does not inherit ADMIN (server/utils/permissions.ts— only ADMIN is a superset). So IT users clicking those links are bounced bymiddleware/01.permission.global.ts.server/api/search/employees.get.tsis alsoADMIN. (Note: the dashboard-consolidation work in Consolidate the 7 role dashboards into one role-aware /dashboard #282 changes how these tiles are gated — reconcile there.)server/api/session/schedule/all.get.tsallows[USER_SERVICE, EVALUATOR], but the calendar's "see all sessions" affordance is gatedUSER_SERVICE || ADMIN. An EVALUATOR could call the endpoint directly and see all sessions (not just their own). EVALUATOR is clinical/PHI-cleared so it's not a leak, but it's inconsistent with the UI intent.Impact
P2. Dead-end nav for IT users; endpoint/UI access intent drift. Worth settling as the role model is exercised.
Proposed approach
schedule/allaccess with intended policy (drop EVALUATOR, or document that evaluators may view all).Acceptance criteria
schedule/allaccess matches a documented policy.