PM-6438 - update access to read timesheet managers - #60
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The authorization change is straightforward and covered by tests, with only minor test naming/duplication nits noted.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR tightens read access to the engagement managers list so that only administrators, engagement managers, or members with an accepted/active assignment status (ASSIGNED) can retrieve it, aligning the endpoint with timesheet-approval authority expectations.
Changes:
- Restricts
EngagementManagersService.findAllread access by requiringengagementAssignment.status = ASSIGNED. - Updates unit tests to validate the new
ASSIGNEDstatus filter and forbidden behavior when the assignment is not accepted.
| File | Description |
|---|---|
src/engagements/managers/engagement-managers.service.ts |
Adds AssignmentStatus.ASSIGNED constraint to the assignment lookup used for read authorization. |
src/engagements/managers/engagement-managers.service.spec.ts |
Extends tests to assert the new status-filtered query and forbidden access when no accepted assignment is found. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+389
to
403
| it("refuses a selected member who has not accepted the assignment", async () => { | ||
| db.engagementAssignment.findFirst.mockResolvedValue(null); | ||
|
|
||
| await expect(service.findAll("eng1", member)).rejects.toBeInstanceOf( | ||
| ForbiddenException, | ||
| ); | ||
| }); | ||
|
|
||
| it("refuses a rejected member", async () => { | ||
| db.engagementAssignment.findFirst.mockResolvedValue(null); | ||
|
|
||
| await expect(service.findAll("eng1", member)).rejects.toBeInstanceOf( | ||
| ForbiddenException, | ||
| ); | ||
| }); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This pull request enhances the authorization logic for retrieving engagement managers by ensuring that only members with an accepted assignment status can access the list. It also updates the associated tests to verify the new access restrictions.
Authorization improvements:
findAllmethod inEngagementManagersServiceto require that a member's assignment status isASSIGNEDbefore allowing access, adding an explicit check on the assignment status.AssignmentStatusimport from@prisma/clientto both the service and its test file to support the new status check. [1] [2]Test coverage enhancements: