- Assignees restricted to recruiter-role users (role id resolved from the roles table per request, not hardcoded); server 422s any other role on create and update - New GET /tasks/assignees/fetch: active recruiter users for the picker, separate from /users/fetch so assigning never needs rbac_users.view - Creation gated to system_administrator / hr_administrator / recruiter: allowed role ids searched from the DB and compared to the callers role_id, on top of the tasks.create permission tag - manual/005_tasks_rbac_restrict.sql: permission DB follows suit - hiring_manager / department_head / ceo swap tasks_management for a view-only tasks_viewer bundle (idempotent, auto-applies at boot) - UI: assignee dropdown lists recruiters from the new endpoint with required-field validation; recruiters get an assign-to-me default; the New Task button honours the creator roles Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| app.py | ||
| models.py | ||
| serializers.py | ||
| views.py | ||