Skip to content

Spike: Backend Endpoint Strategy for Course Authoring Flag #372

Description

@BryanttV

Description

Investigate how authorization-related backend endpoints should consistently account for the status of the authz.enable_course_authoring Waffle Flag, ensuring that the exposure and validation of roles, permissions, scopes, and assignments associated with course authoring align with the availability of the feature.

Questions to Answer

  • Which backend endpoints should account for the status of the authz.enable_course_authoring Waffle Flag?
  • How should the Waffle Flag affect the behavior of each endpoint (filtering, validation, authorization, or response content)?
  • Should this logic be implemented centrally within the framework or explicitly in each endpoint?

Deliverables

  • Inventory of endpoints that should account for the status of the Waffle Flag.
  • Definition of expected behavior for each endpoint when the feature is enabled vs. disabled.
  • Proposal for a consistent strategy to incorporate this logic into the backend, taking into account that the flag will be deprecated in the next releases. The design must ensure that removing the feature flag in the future will require minimal to no refactoring.
  • Strategy to verify performance (load testing, response times, etc.) to ensure the new validation logic does not degrade the backend's efficiency.
  • Analysis of risks, impact, and architectural considerations.
  • High-level estimate for implementing the proposed solution.

Activity

  1. moved this to In Grooming in RBAC AuthZ Boardon Jul 28, 2026
  2. moved this from In Grooming to In Progress in RBAC AuthZ Boardon Jul 30, 2026
  3. mariajgrimaldi commented on Aug 18, 2026

    @mariajgrimaldi
    Member

    Here's a document for the role assignment visibility issue we're currently having. It explains the current state of things and why we need to move away from it; it also makes a plan for how to move forward to a more sustainable solution:

    https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6670319622/Role+assignment+visibility

  4. moved this from In Progress to Ready for Review in RBAC AuthZ Boardon Aug 20, 2026
  5. BryanttV commented on Sep 1, 2026

    @BryanttV
    ContributorAuthor

    The output of this issue was the Confluence document, and the final proposal is being worked on in the ADR linked to the following issue: #363. I will be closing this issue.

  6. moved this from Ready for Review to Done in RBAC AuthZ Boardon Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

willowReleased in Willow

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions