TenantAtlas/app
ahmido 55166cf9b8 Spec 083: Required permissions hardening (canonical /admin/tenants, DB-only, 404 semantics) (#101)
Implements Spec 083 (Canonical Required Permissions manage surface hardening + issues-first UX).

Highlights:
- Enforces canonical route: /admin/tenants/{tenant}/required-permissions
- Legacy tenant-plane URL /admin/t/{tenant}/required-permissions stays non-existent (404)
- Deny-as-not-found (404) for non-workspace members and non-tenant-entitled users
- Strict tenant resolution (no cross-plane fallback)
- DB-only render (no external provider calls on page load)
- Issues-first layout + canonical next-step links (re-run verification -> /admin/onboarding)
- Freshness/stale detection (missing or >30 days -> warning)

Tests (Sail):
- vendor/bin/sail artisan test --compact tests/Feature/RequiredPermissions
- vendor/bin/sail artisan test --compact tests/Unit/TenantRequiredPermissionsFreshnessTest.php tests/Unit/TenantRequiredPermissionsOverallStatusTest.php

Notes:
- Filament v5 / Livewire v4 compliant.
- No destructive actions added in this spec; link-only CTAs.

Co-authored-by: Ahmed Darrazi <ahmeddarrazi@MacBookPro.fritz.box>
Reviewed-on: #101
2026-02-08 23:13:25 +00:00
..
Console/Commands feat: workspace context enforcement + ownership safeguards (#86) 2026-02-02 23:00:56 +00:00
Exceptions feat/032-backup-scheduling-mvp (#34) 2026-01-05 04:22:13 +00:00
Filament Spec 083: Required permissions hardening (canonical /admin/tenants, DB-only, 404 semantics) (#101) 2026-02-08 23:13:25 +00:00
Http Spec 081: Provider connection cutover (#98) 2026-02-08 11:28:51 +00:00
Jobs Spec 081: Provider connection cutover (#98) 2026-02-08 11:28:51 +00:00
Listeners 056-remove-legacy-bulkops (#65) 2026-01-19 23:27:52 +00:00
Livewire Spec 078: Operations tenantless canonical detail (#95) 2026-02-07 09:07:26 +00:00
Models Spec 081: Provider connection cutover (#98) 2026-02-08 11:28:51 +00:00
Notifications 073-unified-managed-tenant-onboarding-wizard (#90) 2026-02-04 23:30:55 +00:00
Observers Spec 081: Provider connection cutover (#98) 2026-02-08 11:28:51 +00:00
Policies feat(spec-080): workspace-managed tenant administration migration (#97) 2026-02-07 19:45:13 +00:00
Providers Spec 081: Provider connection cutover (#98) 2026-02-08 11:28:51 +00:00
Rules feat/049-backup-restore-job-orchestration (#56) 2026-01-11 15:59:06 +00:00
Services Spec 083: Required permissions hardening (canonical /admin/tenants, DB-only, 404 semantics) (#101) 2026-02-08 23:13:25 +00:00
Support feat: action-surface contract inspect affordance + clickable rows (#100) 2026-02-08 20:31:36 +00:00