Skip to content

feat(api-reference): show required permissions from x-epilot-permissions - #157

Merged
anttiviljami merged 1 commit into
mainfrom
feat/required-permissions-in-api-reference
Sep 25, 2026
Merged

anttiviljami merged 1 commit into
mainfrom
feat/required-permissions-in-api-reference

Conversation

@anttiviljami

Copy link
Copy Markdown
Member

Summary

Implements the docs part of RFC: Required Permissions in API Specs. Operations that declare x-epilot-permissions in their OpenAPI spec now show a Required permissions note at the top of the operation in the API reference, linking to the Grant Actions page.

x-epilot-permissions:
  - action: user:invite
  - anyOf:
      - action: role:assign
      - action: role:*

→ Required permissions: user:invite and one of role:assign or role:*. [] renders as "none – any authenticated caller".

  • src/utils/openapi-permissions.ts: pure function that renders the extension into operation descriptions (Redoc ignores unknown x- extensions).
  • RedocPage.tsx: still loads the spec at runtime from docs.api.epilot.io, so the reference stays live. It enriches the spec, then renders it. If loading fails, it falls back to plain Redoc. The download button still points to the original spec URL.
  • grant-actions.md: short note on the extension.

APIs without the extension render exactly as before. The companion Spectral rule is in https://gitlab.com/e-pilot/platform/epilot-ci/-/merge_requests/197.

Test plan

  • npm run build passes
  • eslint passes on changed files
  • Dev server + Playwright with a mocked user.yaml (x-epilot-permissions added to inviteUser and getMeV2): the note renders with anyOf and empty-list variants
  • Entity API (no annotations): all 88 operations render, no page errors, download link unchanged

🤖 Generated with Claude Code

https://claude.ai/code/session_01C2A97XBNr735zXYDgBMs45


Generated by Claude Code

Renders the x-epilot-permissions OpenAPI extension as a "Required
permissions" note at the top of each operation in the API reference.
Specs are still loaded at runtime from docs.api.epilot.io, then enriched
before rendering; falls back to plain Redoc if loading fails.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01C2A97XBNr735zXYDgBMs45
@anttiviljami
anttiviljami merged commit 1679dab into main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant