Skip to content

PM-6515 Allow Talent Managers to view non-member projects -> dev - #2428

Merged
jmgasper merged 1 commit into
devfrom
PM-6515
Oct 2, 2026
Merged

jmgasper merged 1 commit into
devfrom
PM-6515

Conversation

@jmgasper

@jmgasper jmgasper commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Related JIRA Ticket

PM-6515

What's in this PR?

Talent Managers can list non-internal projects in Work Manager but the UI rejects their project workspace and challenges unless they are project members. The shared checkProjectAccess helper now accepts both Talent Manager and Topcoder Talent Manager roles for projects successfully returned by the projects API.

The API remains responsible for internal-project membership restrictions. Missing or rejected project data still denies access, and project/challenge mutation checks remain unchanged. Function documentation and the Work app README explain the access policy. Regression tests exercise normalized role names, workspace rendering, project challenge fetching, internal-project API rejection, and existing membership/mutation restrictions.

Reviewed projects-api-v6 on current dev: its project-read service and project-context interceptor already implement the required non-internal access and internal active-membership restrictions, so no API change is needed.

Validation

  • yarn lint: passed
  • NODE_OPTIONS=--max-old-space-size=8192 yarn run build: passed (default Node heap was insufficient; source-map, CSS-order, and bundle-size warnings remain in unrelated dependencies/styles)
  • UI focused tests: 55 passed across permissions utilities, project route guard, and challenge list page.
  • Existing API authorization tests: 119 passed across project service, permission service, and project-context interceptor.

Manual QA

  1. Sign in as a Talent Manager who is not a member of a non-internal project.
  2. Open that project from the Projects list or visit /projects/:projectId/challenges directly; project details and challenges should load.
  3. Try an internal project without active membership; access should remain denied.
  4. Confirm project and challenge mutation controls still require their existing permissions.

@jmgasper
jmgasper requested a review from kkartunov as a code owner October 2, 2026 05:55
@jmgasper
jmgasper merged commit b96dc1f into dev Oct 2, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant