Skip to content

Allow team owners to edit their application roles#6555

Merged
cstns merged 4 commits intomainfrom
6508_prevent-owners-from-locking-themselves-out-of-applications
Jan 30, 2026
Merged

Allow team owners to edit their application roles#6555
cstns merged 4 commits intomainfrom
6508_prevent-owners-from-locking-themselves-out-of-applications

Conversation

@cstns
Copy link
Contributor

@cstns cstns commented Jan 22, 2026

Description

Simplified continuation of #6478 in which we exposed restricted applications to team owners (in the team members area).

Now, while team owners can restrict their access to certain applications they can easily revert that too.

owner-app-lockout.mp4

I took this route because it was the simplest to implement after #6487. I can go ahead with the full restriction for owner to prevent them from assigning themselves and/or other owners an application role of none if needed

Related Issue(s)

closes #6508

Checklist

  • I have read the contribution guidelines
  • Suitable unit/system level tests have been added and they pass
  • Documentation has been updated
    • Upgrade instructions
    • Configuration details
    • Concepts
  • Changes flowforge.yml?
    • Issue/PR raised on FlowFuse/helm to update ConfigMap Template
    • Issue/PR raised on FlowFuse/CloudProject to update values for Staging/Production
  • Link to Changelog Entry PR, or note why one is not needed.

Labels

  • Includes a DB migration? -> add the area:migration label

@codecov
Copy link

codecov bot commented Jan 22, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.62%. Comparing base (b1cff0e) to head (49152eb).
⚠️ Report is 83 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #6555   +/-   ##
=======================================
  Coverage   76.62%   76.62%           
=======================================
  Files         398      398           
  Lines       20093    20093           
  Branches     4836     4836           
=======================================
  Hits        15397    15397           
  Misses       4696     4696           
Flag Coverage Δ
backend 76.62% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Contributor

@dimitrieh dimitrieh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@cstns Ideally, we make some adjustments to make this UI less confusing :) See our chat : https://flowfuse.slack.com/archives/D09MYHTTTKR/p1769089990916549

- Extend `roles` object by replacing `none` with 'no access' label.
- Replace 'Role' label with 'Access' in team members table.
- Enhance dialog text formatting for better user clarity.
@knolleary
Copy link
Member

Failing UI tests appear related

Copy link
Contributor

@dimitrieh dimitrieh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed with @cstns

@cstns cstns merged commit 4164996 into main Jan 30, 2026
33 of 34 checks passed
@cstns cstns deleted the 6508_prevent-owners-from-locking-themselves-out-of-applications branch January 30, 2026 17:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent Team Owners from locking themselves out of applications via RBAC

3 participants