Skip to content

Permitted roles for restricted pages - #4112

Open
sascha-karnatz wants to merge 5 commits into
mainfrom
permitted-roles-for-restricted-pages
Open

Permitted roles for restricted pages#4112
sascha-karnatz wants to merge 5 commits into
mainfrom
permitted-roles-for-restricted-pages

Conversation

@sascha-karnatz

@sascha-karnatz sascha-karnatz commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Note

There was a previous PR #4102 that used restricted_roles instead of permitted_roles as column.

What is this pull request for?

Add a permitted_roles column to the Page model to extend the restricted page behavior. This way it is possible restrict the access to pages only for a smaller set of users with a given role.

Notable changes (remove if none)

There is an addition to the MemberUser permission that is now evaluating also the permitted_roles column on the page. The default value is "member" and it should behave same way as before.

Screenshots

CleanShot 2026-07-29 at 11 52 13@2x

Checklist

  • I have followed Pull Request guidelines
  • I have added a detailed description into each commit message
  • I have added tests to cover this change

@codecov

codecov Bot commented Jul 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.28%. Comparing base (6d699a2) to head (cc39279).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4112   +/-   ##
=======================================
  Coverage   98.27%   98.28%           
=======================================
  Files         351      352    +1     
  Lines        9224     9247   +23     
=======================================
+ Hits         9065     9088   +23     
  Misses        159      159           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tvdeyen tvdeyen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a nice feature.

Comment thread config/alchemy/config.yml Outdated
Comment thread spec/dummy/config/initializers/alchemy.rb Outdated
Comment thread app/models/alchemy/page.rb
Comment thread app/models/alchemy/page.rb Outdated
Comment thread app/javascript/alchemy_admin/components/conditional_field.js
Comment thread app/components/alchemy/admin/page_permitted_roles_select.rb Outdated
@tvdeyen tvdeyen added the enhancement New feature or enhancement label Jul 29, 2026
@tvdeyen tvdeyen added this to the 8.4 milestone Jul 29, 2026
@sascha-karnatz
sascha-karnatz force-pushed the permitted-roles-for-restricted-pages branch from f87322a to 89fe4b0 Compare July 30, 2026 07:49
sascha-karnatz added a commit to AlchemyCMS/alchemy_i18n that referenced this pull request Jul 30, 2026
These translations all translated by Claude Opus 5.

Ref: AlchemyCMS/alchemy_cms#4112
@sascha-karnatz
sascha-karnatz force-pushed the permitted-roles-for-restricted-pages branch from 89fe4b0 to db959bc Compare August 4, 2026 07:34
@sascha-karnatz
sascha-karnatz changed the base branch from main to conditional-field-component August 4, 2026 07:36
Base automatically changed from conditional-field-component to main August 4, 2026 08:06
Add a new permitted_roles column with a space separated list of roles, that can access a page. The default values is "member" to support the same behavior as before.
...to test that feature better in the dummy app.
Add getter and setter to the page model to split and join the group collection. Extend the set_restrictions_to_child_pages behavior to update permitted_roles as well. It was necessary to move from before_save to after_save to update restricted and permitted_roles of child pages. Otherwise inherit_restricted_status would read old data from the database.
Test if the user has the correct role to read the page. This change only affects the MemberUser permission. GuestUser can't see restricted pages and AuthorUser includes the MemberUser module. If Alchemy will be extended by other roles (like restricted_test in the Dummy app), it is necessary to create new abilities to prevent misconfigurations (like to many redirects).
Provide a new PagePermittedRolesSelect view component to render a select with all configured permitted_roles. The select is only visible if the restricted checkbox is enabled.
Remove the width for the input-column class. Without the width this class can also be used for the PagePermittedRolesSelect and the missing width does not have a visual difference in all other place where the class is used (ElementScheduleTimestamps and PagePublicationFields).
@tvdeyen
tvdeyen force-pushed the permitted-roles-for-restricted-pages branch from db959bc to cc39279 Compare August 4, 2026 08:06

@tvdeyen tvdeyen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we need to adjust the permission to use a scope as well. There are likely more places that we need to check

@@ -70,7 +70,7 @@ def alchemy_member_rules
end

can :read, Alchemy::Page, Alchemy::Page.published.from_current_site do |p|

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need a scope here as well in order to get the correct collection of pages by Alchemy::Page.accessible_by(current_ability)? We use that in

@pages = Alchemy::Page.accessible_by(current_ability, :index)

and probably other places. Can we add a spec to confirm?

p.public? && p.site == Alchemy::Current.site && p.readable_by?(@user)
end

can :read, Alchemy::Node, Alchemy::Node.available_to_members do |node|

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We probably need to adjust the Alchemy::Node.available_to_members scope as well.

@tvdeyen tvdeyen self-assigned this Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants