Overview

The following permissions determine access to high-level features in the XB UI, and will allow the UI to perform a simple if (boolean) { show(); }-style check:

  1. Administer Page Template (for PageRegion config entities, which together make up the "page template") → show the Move to global region option in context menus … or not
  2. Administer Sections (for Pattern config entities) → show "Create section" in context menus … or not (⚠️ list of sections to use is always available!)
  3. Administer Code Components (for JavaScriptComponent and AssetLibrary config entities) → show "Add component" and "Code" in sidebar + request /xb/api/js_component … or not

Partially blocked on #3508694: Permissions for XB config entity types, because Pattern doesn't yet have the appropriate permission.

Proposed resolution

diff --git a/src/Controller/ExperienceBuilderController.php b/src/Controller/ExperienceBuilderController.php
index 94dfed312..f1878b80f 100644
@@ -110,6 +111,11 @@ HTML;
             'jsFooter' => $this->assetRenderer->renderJsFooterAssets($preview_assets),
           ],
           'xbModulePath' => $xb_module_path,
+          'permissions' => [
+            'globalRegion' => $this->currentUser->hasPermission(PageRegion::ADMIN_PERMISSION),
+            'sections' => $this->currentUser->hasPermission(Pattern::ADMIN_PERMISSION),
+            'codeComponents' => $this->currentUser->hasPermission(JavaScriptComponent::ADMIN_PERMISSION),
+          ],
         ],
       ],
       // Note: the tokens here are under our control, and this accepts no user

User interface changes

None; that's for #3516641: Make the XB UI show only UI elements/operations available to the current user and related issues to tackle.

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

wim leers created an issue. See original summary.

wim leers’s picture

Title: Pass current user's XB permissions to the XB UI » Pass current user's XB high-level permissions to the XB UI
Issue tags: +stable blocker, +sprint
wim leers’s picture

Title: Pass current user's XB high-level permissions to the XB UI » Update `ExperienceBuilderController` to pass current user's XB high-level permissions to the client

penyaskito made their first commit to this issue’s fork.

penyaskito’s picture

Status: Active » Needs review

MR on top of #3508694: Permissions for XB config entity types.
The actual thing to review here is since 2696a5.

wim leers’s picture

Assigned: Unassigned » penyaskito
Status: Needs review » Needs work
wim leers’s picture

#3508694: Permissions for XB config entity types is in, this now needs a reroll :)

penyaskito’s picture

Status: Needs work » Needs review
wim leers’s picture

Status: Needs review » Needs work

🏓

penyaskito’s picture

Status: Needs work » Needs review
wim leers’s picture

Status: Needs review » Needs work

One last tiny thing and then this will be able to land! 🚀

penyaskito’s picture

Status: Needs work » Needs review

🏓

wim leers’s picture

Assigned: penyaskito » Unassigned
Status: Needs review » Reviewed & tested by the community

wim leers’s picture

Status: Reviewed & tested by the community » Fixed
nagwani’s picture

Issue tags: -sprint

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.