Skip to content

feat: add advanced settings view permission for course roles#272

Draft
bra-i-am wants to merge 4 commits into
openedx:mainfrom
eduNEXT:bc/add-advanced-settings-view-permission
Draft

feat: add advanced settings view permission for course roles#272
bra-i-am wants to merge 4 commits into
openedx:mainfrom
eduNEXT:bc/add-advanced-settings-view-permission

Conversation

@bra-i-am
Copy link
Copy Markdown

@bra-i-am bra-i-am commented Apr 27, 2026

Description

Adds COURSES_VIEW_ADVANCED_SETTINGS permission to enable read-only access to advanced settings for the course_auditor role. Also adds COURSES_MANAGE_ADVANCED_SETTINGS to course_editor role for full access.
This change supports the read-only access feature for auditors in the Pages and Resources section of frontend-app-authoring MFE, allowing users with course_auditor role to view (but not modify) advanced settings.

Supporting information

Changes

  • permissions.py: Added COURSES_VIEW_ADVANCED_SETTINGS permission
  • roles.py: Added COURSES_VIEW_ADVANCED_SETTINGS to COURSE_AUDITOR_PERMISSIONS and COURSE_EDITOR_PERMISSIONS; added COURSES_MANAGE_ADVANCED_SETTINGS to COURSE_EDITOR_PERMISSIONS
  • authz.policy: Added policy rules for both permissions

How to test

  1. Assign course_auditor role to a user for a specific course
  2. The user should be able to access the Advanced Settings page in Studio but all form fields should be disabled (read-only mode)
  3. Assign course_editor role to a user
  4. The user should have full access (read + write) to Advanced Settings

Merge checklist

Check off if complete or not applicable:

  • Version bumped
  • Changelog record added
  • Documentation updated (not only docstrings)
  • Fixup commits are squashed away
  • Unit tests added/updated
  • Manual testing instructions provided
  • Noted any: Concerns, dependencies, migration issues, deadlines, tickets

@openedx-webhooks openedx-webhooks added the open-source-contribution PR author is not from Axim or 2U label Apr 27, 2026
@openedx-webhooks
Copy link
Copy Markdown

openedx-webhooks commented Apr 27, 2026

Thanks for the pull request, @bra-i-am!

This repository is currently maintained by @openedx/committers-openedx-authz.

Once you've gone through the following steps feel free to tag them in a comment and let them know that your changes are ready for engineering review.

🔘 Get product approval

If you haven't already, check this list to see if your contribution needs to go through the product review process.

  • If it does, you'll need to submit a product proposal for your contribution, and have it reviewed by the Product Working Group.
    • This process (including the steps you'll need to take) is documented here.
  • If it doesn't, simply proceed with the next step.
🔘 Provide context

To help your reviewers and other members of the community understand the purpose and larger context of your changes, feel free to add as much of the following information to the PR description as you can:

  • Dependencies

    This PR must be merged before / after / at the same time as ...

  • Blockers

    This PR is waiting for OEP-1234 to be accepted.

  • Timeline information

    This PR must be merged by XX date because ...

  • Partner information

    This is for a course on edx.org.

  • Supporting documentation
  • Relevant Open edX discussion forum threads
🔘 Get a green build

If one or more checks are failing, continue working on your changes until this is no longer the case and your build turns green.

🔘 Update the status of your PR

Your PR is currently marked as a draft. After completing the steps above, update its status by clicking "Ready for Review", or removing "WIP" from the title, as appropriate.


Where can I find more information?

If you'd like to get more details on all aspects of the review process for open source pull requests (OSPRs), check out the following resources:

When can I expect my changes to be merged?

Our goal is to get community contributions seen and reviewed as efficiently as possible.

However, the amount of time that it takes to review and merge a PR can vary significantly based on factors such as:

  • The size and impact of the changes that it introduces
  • The need for product review
  • Maintenance status of the parent repository

💡 As a result it may take up to several weeks or months to complete a review and merge your PR.

Copy link
Copy Markdown
Contributor

@BryanttV BryanttV left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot, @bra-i-am. The code looks good. I just have a few comments.

Comment thread openedx_authz/constants/roles.py
Comment thread openedx_authz/engine/config/authz.policy
Comment thread openedx_authz/tests/test_engine_utils.py
Comment thread openedx_authz/tests/test_enforcement.py
Copy link
Copy Markdown
Contributor

@MaferMazu MaferMazu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A quick question: Why did we need to add the " View advanced settings permission"? In the description, you mention consistency, but I would like to understand it more.

The PR looks good to me! Thanks @bra-i-am
Note: Please bump the version (from 1.15 to 1.16) and add the record to the changelog.

@bra-i-am bra-i-am force-pushed the bc/add-advanced-settings-view-permission branch from 8298cd5 to 0f8ce2a Compare May 14, 2026 15:32
@bra-i-am
Copy link
Copy Markdown
Author

@MaferMazu, @BryanttV, thank you so much for your help reviewing this PR!! ✨

Mafer, the reason to add the COURSES_VIEW_ADVANCED_SETTINGS permission (instead of just using COURSES_MANAGE_ADVANCED_SETTINGS) is to support a read-only access for the course_auditor role:

  • course_auditor → can see the page and menu item, but all fields are read-only
  • course_editor / course_staff / course_admin get both VIEW and MANAGE → full read/write access

Note

CONTEXT
The issue arose while working on the permissions for Pages and Resources. I found that this view https://github.com/openedx/frontend-app-authoring/pull/3031/changes#r3162572209 requests the advanced_settings endpoint to retrieve information for Progress, and I discovered that the endpoint lacked read-only permissions.

This is also done to follow the same pattern already established in the repo for other sections — for example, COURSES_VIEW_GRADING_SETTINGS and COURSES_VIEW_SCHEDULE_AND_DETAILS exist with their EDIT_* / MANAGE_* counterparts

BTW, I already bumped the version and modified the CHANGELOG. Please let me know if anything else is required. Thanks again!

@bra-i-am bra-i-am force-pushed the bc/add-advanced-settings-view-permission branch from 0f8ce2a to 61bc401 Compare May 14, 2026 15:39
@MaferMazu MaferMazu self-requested a review May 14, 2026 15:55
Comment thread CHANGELOG.rst
=====

* Add ``COURSES_VIEW_ADVANCED_SETTINGS`` permission and assign it to ``course_auditor``, ``course_editor``, ``course_staff``, and ``course_admin`` roles to enable read-only access to Advanced Settings.
* Assign existing ``COURSES_MANAGE_ADVANCED_SETTINGS`` permission to the ``course_editor`` role to grant full read/write access to Advanced Settings.
Copy link
Copy Markdown
Contributor

@MaferMazu MaferMazu May 14, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed the approval because I thought you hadn't added the manage_advanced_settings. Details: #288

Is there a place where we say the editor has advanced settings permission? If not, can we remove that permission for the editor role?

@MaferMazu
Copy link
Copy Markdown
Contributor

@bra-i-am thanks for the explanation.

As you said, course_editor should be able to edit and view pages and resources. If something in "progress" needs advanced settings, it is okay. He can't access them because the course_editor doesn't have access to manage or view them, but he can edit the rest. Details #288
What do you think?

@bra-i-am bra-i-am marked this pull request as draft May 14, 2026 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

open-source-contribution PR author is not from Axim or 2U

Projects

Status: Waiting on Author
Status: No status

Development

Successfully merging this pull request may close these issues.

5 participants