feat(15-05): getWidgets filters via ModuleAccessService (D-22, PERM-07)
- DashboardModule imports ModuleRegistryModule to inject ModuleAccessService - getWidgets(userId, tenantId, role) runs the existing findMany unchanged first, then calls getAccessibleModuleIds exactly once — only if a loaded widget's type is in WIDGET_MODULE_MAP (currently always empty, so no lookup runs today); unresolved module slugs fail closed - DashboardController.getWidgets forwards tenantId + role from the JWT - dashboard.service.spec.ts (8 tests, TDD-GREEN): covers every <behavior> case incl. D-03 ADMIN bypass, adjacency/empty/ordering/idempotency, and fail-closed on an unresolved Module slug - pnpm --filter @tessera/api test: 457/457 green; type-check clean - manual e2e against local API + DB container: empty WIDGET_MODULE_MAP leaves an existing user's widget count unchanged (2/2 clock+search survived the filter), throwaway verification user/rows removed after
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { ModuleRegistryModule } from '../module-registry/module-registry.module';
|
||||
import { DashboardController } from './dashboard.controller';
|
||||
import { DashboardService } from './dashboard.service';
|
||||
|
||||
@@ -9,9 +10,13 @@ import { DashboardService } from './dashboard.service';
|
||||
* - DashboardService: CRUD for per-user dashboard layouts and widget instances
|
||||
* - DashboardController: REST API for layout and widget operations
|
||||
*
|
||||
* Imports ModuleRegistryModule so DashboardService can inject
|
||||
* ModuleAccessService for the D-22 widget-module filter (Plan 15-05).
|
||||
*
|
||||
* Exports DashboardService so downstream modules can access layout/widget data.
|
||||
*/
|
||||
@Module({
|
||||
imports: [ModuleRegistryModule],
|
||||
controllers: [DashboardController],
|
||||
providers: [DashboardService],
|
||||
exports: [DashboardService],
|
||||
|
||||
Reference in New Issue
Block a user