Files
Stirling-PDF/app
Reece ae66b8a5e1 fix(policies): gate policy editing to team leaders on SaaS, not admin
Builds on the org-wide policy model (#6625): reads/runs are open to all; create/edit/delete is gated by PolicyController.requirePolicyEditingAllowed, which was admin-only. On SaaS that's the wrong role — there is a single global admin for the whole deployment, never one per org — so org users couldn't edit policies at all. Introduce a PolicyManagementAuthority strategy: self-hosted keeps the global-admin check (AdminPolicyManagementAuthority); SaaS uses the leader of the user's team (TeamLeaderPolicyManagementAuthority -> TeamSecurityExpressions.isCurrentUserTeamLeader). The proprietary policy layer stays decoupled from the team model via the interface + profile-scoped beans.

Tests: TeamSecurityExpressionsTest (leader/member/no-membership/no-team/unauthenticated), plus delegation tests for both authority beans.
2026-06-11 22:59:00 +01:00
..