Repository navigation
Conversation
|
Thanks for the pull request, @BryanttV! This repository is currently maintained by Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review. 🔘 Get product approvalIf you haven't already, check this list to see if your contribution needs to go through the product review process.
🔘 Provide contextTo help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:
🔘 Get a green buildIf one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green. DetailsWhere can I find more information?If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources: When can I expect my changes to be merged?Our goal is to get community contributions seen and reviewed as efficiently as possible. However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:
💡 As a result it may take up to several weeks or months to complete a review and merge your PR. |
GET /api/authz/v1/users/{username}/assignments/ now reuses
TeamMemberAssignmentInlineSerializer: adds scope_display_name (resolved in
bulk per page) and removes is_superadmin from the response.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
091456e to
5d33bd7
Compare
|
@BryanttV wouldn't removing is_superadmin from the response break the current frontend behavior? or has this been changed in the frontend too? |
rodmgwgu
left a comment
There was a problem hiding this comment.
Thanks for this! It's looking good, just added some comments to take into account.
| Unreleased | ||
| ********** | ||
|
|
||
| 1.25.0 - 2026-10-07 |
There was a problem hiding this comment.
This will need updating before we merge, we are currently at 1.28.0.
| ``GET /api/authz/v1/users/<username>/assignments/`` returns the same assignment | ||
| shape (``role``, ``org``, ``scope``, ``scope_display_name``, ``permission_count``), | ||
| produced by the same serializer, so both endpoints cannot drift apart. The | ||
| ``is_superadmin`` field is not part of this shape. The assignment-grouped |
There was a problem hiding this comment.
It sounds to me that this comment about is_superadmin is out of place, I think we don't need to mention it as it will no longer be in the code and could be confusing for someone without the historical context.
| return _sort_by_field(assignments, sort_by, order, UserAssignmentSortField) | ||
|
|
||
|
|
||
| def inject_scope_display_names(assignments: list[dict]) -> None: |
There was a problem hiding this comment.
Would it make sense to define a dataclass to pass instead of a dict (for the assignments param)? To make this more type safe.
rodmgwgu
left a comment
There was a problem hiding this comment.
Tested in my local and it's working as described. Thanks!
There was a problem hiding this comment.
Tested in my local with the current changes of admin-console, works great, thanks!
Page is stil working, no errors
Endpoint body response
{
"count": 4,
"next": null,
"previous": null,
"results": [
{
"role": "course_staff",
"org": "CORG",
"scope": "course-v1:CORG+*",
"permission_count": 31,
"scope_display_name": ""
},
{
"role": "course_staff",
"org": "CORG",
"scope": "course-v1:CORG+CARLOS101+2026_2",
"permission_count": 31,
"scope_display_name": "My Course"
},
{
"role": "library_user",
"org": "CORG",
"scope": "lib:CORG:*",
"permission_count": 3,
"scope_display_name": ""
},
{
"role": "library_user",
"org": "CORG",
"scope": "lib:CORG:LIB101",
"permission_count": 3,
"scope_display_name": "MyLibrary"
}
]
}

Closes #511
Description
GET /api/authz/v1/users/{username}/assignments/(TeamMemberAssignmentsAPIView) returned a different assignment shape than the inlineassignmentsarray ofGET /api/authz/v1/users/introduced in #451 (ADR 0024). As a result, the Team Member detail view could only label scopes with their raw key (e.g.lib:Org1:LIB1).This PR makes both endpoints return the same assignment shape.
Changes
TeamMemberAssignmentsAPIViewnow serializes withTeamMemberAssignmentInlineSerializer, so both endpoints share one serializer and cannot drift apart again.scope_display_name(CourseOverview.display_namefor courses,learning_package.titlefor libraries).is_superadmin.get_scope_display_name_map: one batched lookup per scope type per page, no N+1 queries. Glob scopes, superadmin entries and missing courses/libraries return"", the same asGET /api/authz/v1/users/.scoperemains the stable machine identifier.inject_scope_display_namesinrest_api/utils.py, used by bothTeamMembersAPIViewandTeamMemberAssignmentsAPIView. It replaces the block that was previously inlined inTeamMembersAPIView. It lives next to the other helpers that operate on serialized dicts (sort_assignments,filter_users, ...), andapi/utils.pyis left as the domain layer.scope_display_name.Filtering (
orgs,roles), sorting, and pagination behave as before.GET /api/authz/v1/assignments/(AssignmentsAPIView) is not modified.Response example
{ "count": 2, "next": null, "previous": null, "results": [ { "role": "library_admin", "org": "Org1", "scope": "lib:Org1:LIB1", "scope_display_name": "Intro to CS Library", "permission_count": 11 }, { "role": "library_author", "org": "Org1", "scope": "lib:Org1:*", "scope_display_name": "", "permission_count": 9 } ] }Breaking change
is_superadminis no longer returned byGET /api/authz/v1/users/{username}/assignments/. Clients reading that field must stop relying on it. This is noted in the changelog and ADR 0024.Testing instructions
lib:Org1:LIB1) and a specific course (course-v1:Org1+CS101+2024)lib:Org1:*) and a platform-level glob (lib:*)GET /api/authz/v1/users/<username>/assignments/.scope_display_nameand nois_superadmin. The library and course show their title and display name. The globs and the missing library show"".orgs,roles,sort_by,order,page, andpage_sizestill work.Merge checklist
Check off if complete or not applicable: