Skip to content

Add compound policy write methods to the policies store #8686

Description

@vitormattos

Part of #8684.

Goal

Add frontend store methods for the compound-policy write endpoints that already exist in the backend.

Do not change Policy Workbench behavior in this issue.

Backend endpoints

Add store methods for:

POST /apps/libresign/api/v1/policies/compound/system/{parentPolicyKey}
PUT  /apps/libresign/api/v1/policies/compound/group/{groupId}/{parentPolicyKey}
PUT  /apps/libresign/api/v1/policies/compound/user/{parentPolicyKey}
PUT  /apps/libresign/api/v1/policies/compound/user/{userId}/{parentPolicyKey}

The request body uses:

{
  values: Record<string, EffectivePolicyValue>
  allowChildOverride?: Record<string, boolean>
}

The backend response contains a policies map.

Response value types are already defined by the backend/OpenAPI contract:

  • system and current-user compound writes return effective policy states;
  • group compound writes return group policy states;
  • target-user compound writes return user policy states.

Use the generated/current API types from the repository. Do not invent parallel response interfaces if an OpenAPI type already exists. Do not edit generated OpenAPI files manually.

Files

Main file:

src/store/policies.ts

Add or update the matching store tests.

Follow the request/response style of the existing single-policy methods:

saveSystemPolicy
saveGroupPolicy
saveUserPreference
saveUserPolicyForUser

Requirements

  • keep the existing single-policy methods unchanged;
  • return the typed policies map from each compound method;
  • do not guess that a group or target-user response is the effective state of the current user;
  • do not add extra effective-state refresh logic here;
  • callers may continue using fetchEffectivePolicies() after a successful save;
  • do not duplicate backend validation;
  • do not add or change backend endpoints.

Tests

Cover each new store method:

  • correct HTTP method;
  • correct URL;
  • values payload;
  • allowChildOverride payload where supported;
  • returned policies map is parsed with the expected response type.

Mock the HTTP layer using the existing store test pattern.

Done when

  • All four compound write endpoints have store methods.
  • The methods return the typed policies map.
  • Existing store methods are unchanged.
  • Unit tests cover the new methods.
  • npm run lint passes.
  • npm run ts:check passes.

Good first issue

This issue only connects existing backend endpoints to the existing frontend policy store. It does not change the Workbench engine or policy rules.

Activity

  1. added theissue type on Sep 24, 2026
  2. nva138 commented on Sep 24, 2026

    @nva138
    Contributor

    Hi @vitormattos, thanks for splitting it up, the path is much clearer now. I'd like to take this one. I'll mirror the existing single-policy methods and add the matching store tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Fields

Priority

None yet

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions