Request course or club admin access in the app #82

Open
opened 2026-10-03 19:44:45 +00:00 by jalenluorion · 0 comments
Member

Goal
Club leaders and TAs should be able to ask for access without leaving CMUCal. Today they fill in a Google Form and wait for someone to check it by hand.

Current state

  • The link is https://forms.gle/DaaShMuQpbYiSNLn6 in web/src/app/components/ModalUploadOne.tsx ("No available calendars?").
  • Org roles are admin and manager (ORG_ROLES in api/app/utils/auth.py). Managers add admins with create_admin / bulk_create_admins in api/app/api/organizations.py. Site admins come from the Keycloak group PROJECT_ADMIN_GROUP.
  • api/app/api/admin.py registers an empty /api/admin blueprint. The web app has no site-admin page, only /manager.

Scope

  • access_requests table (user, org or requested new org name, optional category, role, reason, status, reviewer, timestamps) plus an alembic migration.
  • API: create a request; list pending requests for orgs you manage (can_manage_org) or all of them (site admin); approve (calls create_admin, or creates the org for a new-org request) and deny. Block duplicate pending requests.
  • Web: replace the form link with an in-app request form (search orgs, or "my org is not listed").
  • Web: a Requests section in ManagerDashboard.tsx, plus a minimal site-admin list for new-org requests.
  • The requester sees the status of their request.
  • API tests for permissions (who can see and approve what).

Done when

  • A user can request access, a manager or site admin can approve it in the app, and the user can then upload to that org.
  • The Google Form link is gone.
**Goal** Club leaders and TAs should be able to ask for access without leaving CMUCal. Today they fill in a Google Form and wait for someone to check it by hand. **Current state** - The link is `https://forms.gle/DaaShMuQpbYiSNLn6` in `web/src/app/components/ModalUploadOne.tsx` ("No available calendars?"). - Org roles are `admin` and `manager` (`ORG_ROLES` in `api/app/utils/auth.py`). Managers add admins with `create_admin` / `bulk_create_admins` in `api/app/api/organizations.py`. Site admins come from the Keycloak group `PROJECT_ADMIN_GROUP`. - `api/app/api/admin.py` registers an empty `/api/admin` blueprint. The web app has no site-admin page, only `/manager`. **Scope** - [ ] `access_requests` table (user, org or requested new org name, optional category, role, reason, status, reviewer, timestamps) plus an alembic migration. - [ ] API: create a request; list pending requests for orgs you manage (`can_manage_org`) or all of them (site admin); approve (calls `create_admin`, or creates the org for a new-org request) and deny. Block duplicate pending requests. - [ ] Web: replace the form link with an in-app request form (search orgs, or "my org is not listed"). - [ ] Web: a Requests section in `ManagerDashboard.tsx`, plus a minimal site-admin list for new-org requests. - [ ] The requester sees the status of their request. - [ ] API tests for permissions (who can see and approve what). **Done when** - [ ] A user can request access, a manager or site admin can approve it in the app, and the user can then upload to that org. - [ ] The Google Form link is gone.
jalenluorion added this to the Phase 3 milestone 2026-10-03 19:44:45 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#82
No description provided.