A run had one front-end page, the requester's, gated to the initiator. An operator who works one of its steps had no read surface at all: the task lists showed them the task, but the run behind it was reachable only through the admin trace, which is access orchestra instances gated.

What this does

  • One address per run, /orchestra/instance/{instance}, read by everyone the run concerns, so a link works for whoever is entitled to open it. It replaces /orchestra/my-instances/{id}; the requester's list keeps its own path.
  • A read scope deciding who else reads a run: only the person who filed it, its workers (whoever holds or completed a task, plus a holder of reassign orchestra tasks for a task somebody else holds), or its whole audience (everyone a task is offered to). Workers is the default. Set site-wide, overridable per tenant and per workflow, resolved workflow, then tenant, then site: the same precedence and plumbing as retention.
  • No hand-typed URLs in the shipped views. The Reference column gains a Link to the run option and a new Trace link field replaces a custom-text column, both building links from routes, offering them only where the viewer may follow, and carrying the list they were clicked on as the return target.
  • The run's page is a template, orchestra-instance.html.twig, overridable in a theme, receiving the run's parts as data.

For a site already running these views

The shipped views are configuration, so a site that installed them keeps its stored copy: re-import views.view.my_tasks, views.view.my_workflow_instances, views.view.orchestra_processes and views.view.orchestra_completed to pick up the route-based links. Pre-release, so no update hook.

Follow-ups

The card component (CSS, the shared row template) still lives in the engine module, which should carry no presentation; and the labeled-column and status-tag markup exists both in PHP and in Twig. Both are filed separately rather than folded in here.

Issue fork orchestra-3613730

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

mably created an issue. See original summary.

mably’s picture

Title: Let the operator who processed a request read its instance, not only the initiator » Let a run's own people read it, with a read scope the site, tenant or workflow sets
Issue summary: View changes
Status: Active » Needs review

  • mably committed 0c18203b on 1.x
    feat: #3613730 Let a run's own people read it, with a read scope the...
mably’s picture

Status: Needs review » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.