Skip to content

feat: accept workspace.launch as an alternative to platform.manage_infra - #9

Merged
man4ish merged 1 commit into
mainfrom
feat/launcher-workspace-launch-permission
Oct 4, 2026
Merged

man4ish merged 1 commit into
mainfrom
feat/launcher-workspace-launch-permission

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

Launching/stopping/creating a personal IDE workspace is a self-service action, not platform-infrastructure administration -- but every mutating route here required platform.manage_infra, an admin-only permission with no self-service equivalent, so no regular developer account could ever use this feature.

workspace.launch (a new permission in omnibioai-auth's registry, grantable to a regular role like scientist) now satisfies the same gate; platform.manage_infra keeps working unchanged for admin accounts. requireIdentity accepts either a single permission name (every pre-existing call site) or an array where holding any one is sufficient.

Test plan

  • CI=true npx react-scripts test --testPathPattern="server.test.js" -- 37 passed (35 existing + 2 new)
  • Reproduced "insufficient permissions" against the live stack with a real non-admin account, confirmed the fix resolves it end-to-end (after the matching omnibioai-auth permission grant)

🤖 Generated with Claude Code

Launching/stopping/creating a personal IDE workspace is a self-service
action, not platform-infrastructure administration -- but every
mutating route here required platform.manage_infra, an admin-only
permission with no self-service equivalent. workspace.launch
(omnibioai-auth's permission registry, grantable to a regular role
like scientist) now satisfies the same gate; platform.manage_infra
keeps working unchanged for admin accounts. requireIdentity accepts
either a single permission name (every pre-existing call site) or an
array where holding any one is sufficient.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit a4bd0c6 into main Oct 4, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant