lahirujayathilake opened a new pull request, #549:
URL: https://github.com/apache/airavata-custos/pull/549

   ## Problem
   
   Projects and Allocations are a researcher's own views, but the read routes 
required the `core:projects:read` / `core:allocations:read` site privileges. A 
plain allocation member with no site privilege saw nothing on their own project 
and allocation pages.
   
   ## What changed
   
   - Members now see their own projects and allocations by default, no site 
privilege needed.
   - Non-members get a 404, the same as a missing id.
   - Admins with the privilege still get the full listing, unchanged.
   - Applies to the project and allocation read routes (list and detail).
   - Web pages drop their permission gates, since the backend now scopes the 
reads.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to