🛂 fix: Gate App Layout Pessimistically While Capabilities Load - #101
Open
dustinhealy wants to merge 1 commit into
Open
🛂 fix: Gate App Layout Pessimistically While Capabilities Load#101dustinhealy wants to merge 1 commit into
dustinhealy wants to merge 1 commit into
Conversation
The layout guard only rendered AccessDenied once the capabilities query had settled, so during the fetch an unauthorized user briefly saw the full authenticated chrome before the denial appeared. A query error skipped the guard entirely and left the layout rendered indefinitely. Applies the convention the child routes already use: render nothing while loading, PermissionsUnavailable on error, and AccessDenied only on a settled missing capability.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
_applayout guard rendersAccessDeniedonly after the effective-capabilities query has settled:This has two problems for a logged-in user who lacks
ACCESS_ADMIN:AccessDenied. Child data queries are still rejected server-side, so no data is exposed, but the unauthorized user briefly sees the admin panel's layout and navigation.useCapabilities),!isErrorprevents the guard from ever tripping and the layout stays rendered indefinitely.Fix
Applies the same convention the child routes (
access.tsx, etc.) already use, at the layout level: render nothing while loading,PermissionsUnavailable(with its reload affordance) on error, andAccessDeniedonly on a settled missing capability. The gate now fails closed in every non-success state.Testing
tsc --noEmitclean,eslintclean, full test suite (799 tests) passing, from-scratch production build succeeds.