Employees with the extension enabled get a 403 page instead of their payslips #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
views.pyserves exactly one page — the operator console — and 403s anyone who is not the super user:But employees now need
payrollamong their active extensions, otherwise LNbits' per-user route gate (check_user_extension_access,lnbits/decorators.py:420) blocks/payroll/api/v1/my/*with{"detail": "Extension 'payroll' not enabled."}regardless of their invoice key. See36e1643for why the extension therefore cannot live inLNBITS_ADMIN_EXTENSIONS.The result: an employee sees Payroll in their menu, clicks it, and gets a 403. The
/my/*endpoints they can now reach have no UI in front of them.Proposal
Render the page by role rather than refusing it:
/my/contractsand/my/payouts: what they are owed, when the next payday lands, what has been paid, and the CSV button pointed at/my/payouts.csvThe endpoints already exist and are wallet-key scoped, so this is a template/JS change plus a branch in
views.py. It probably wants a wallet picker, since the invoice key scopes payslips to one wallet and a user may have several.Not in scope
The auth model is unchanged —
check_super_useron the operator router, invoice key on the employee router. This only stops an employee-facing route from being a dead end.Found by
Smoke-testing v0.1.0 on bohm: a daily 10 EUR contract paid correctly (14878 sat, both legs settled, ledger row matched), and the employee endpoint was the one surface that had never been exercised.
🤖 Generated with Claude Code
https://claude.ai/code/session_018jy52j9GRZ6XKa1Zt21LLj
Reproduced on bohm. Enabling
payrollfor a non-super-user account and opening the page gives:So the extension is now reachable enough to appear in an employee's menu and still refuses them at the door. This was filed pre-emptively; it is now a live defect.
Confirms the shape of the fix too — the employee's
/my/*endpoints have still never been exercised, because until the extension is enabled for them the per-user gate answers{"detail": "Extension 'payroll' not enabled."}, and once it is enabled the only page route 403s. Both halves have to move together: enabling the extension per account is what unblocks the API, and the role-branched page is what makes it usable.Worth noting for whoever picks this up:
/my/payouts.csvcannot be a plain<a href>like the operator CSV button, becauserequire_invoice_keyneeds the key and an anchor cannot set a header. LNbits does accept it as anapi-keyquery parameter (APIKeyQuery(name="api-key"),lnbits/decorators.py:53), but putting a wallet key in a URL puts it in browser history — fetching with the header and triggering a Blob download is the better route.