Skip to content

fix(react, core): Add a new opt-out prop to Auth0ComponentProvider for skip permission gating - #550

Merged
grandmaester merged 2 commits into
mainfrom
fix/opt-out-flow-added-for-permissions-gating
Sep 29, 2026
Merged

grandmaester merged 2 commits into
mainfrom
fix/opt-out-flow-added-for-permissions-gating

Conversation

@grandmaester

@grandmaester grandmaester commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a disablePermissionEnforcement opt-out prop to Auth0ComponentProvider that allows consumers to bypass permission gating entirely when the auth/profile API is not available/setup in their environment.

Why

Some teams consuming these components have not set up the auth/profile API (used to resolve user permission scopes). Without an opt-out, PermissionProvider falls back to an empty permissions array after a failed fetch, causing all gated actions to be disabled — making the components effectively unusable for those teams.

What

  • packages/core — permission-map.ts: Adds disablePermissionEnforcement?: boolean to PermissionOptions; evaluateRule returns true immediately when set, taking precedence over readOnly
  • packages/react — permission-provider.tsx: Accepts disablePermissionEnforcement prop; short-circuits the fetchPermissions effect (no getPermissions() call, no network request)
  • packages/react — use-permissions.ts: Forwards disablePermissionEnforcement from context into every createPermissionResolver call so all permission flags resolve to true
  • packages/react — spa-provider.tsx / proxy-provider.tsx: Destructure and forward disablePermissionEnforcement from Auth0ComponentProviderProps to PermissionProvider
  • packages/react — auth-types.ts / permissions-types.ts: Type definitions updated across the chain

Packages

  • packages/core
  • packages/react
  • examples

References

Permission gating feature introduced in PRs #484–#486, #494.

Testing

When Readonly Permissions are only provided but disablePermissionEnforcement is true(opt-out):

GMT20260929-092319_Clip_Rohit.Sharma.s.Clip.09_29_2026.mp4

When Readonly Permissions are only provided but disablePermissionEnforcement is null or not set(existing behavior):

GMT20260929-092531_Clip_Rohit.Sharma.s.Clip.09_29_2026.mp4

Same flow has been tested for SPA mode as well.

Note: Even though on Client, disablePermissionEnforcement making things editable and actionable, backend also enforeces scope checks which will most operations if required scopes are not set.

  • This change adds unit test coverage
    • permission-map.test.ts: two new cases — disablePermissionEnforcement grants all flags, takes precedence over readOnly
    • permission-provider.test.tsx: new case — fetch is skipped, all permission flags resolve to true end-to-end
  • Tested for both SPA and RWA flows, all example apps working
  • All existing and new tests complete without errors

Checklist

  • Breaking change
  • Requires docs update
  • Backward compatible

Contributing

@grandmaester grandmaester self-assigned this Sep 29, 2026
@grandmaester grandmaester added the enhancement New feature or request label Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 21534461-54ff-4373-906f-7d3ca0bf3bec


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@grandmaester grandmaester changed the title fix: add skipGating opt-out prop to Auth0ComponentProvider for permission gating fix: add skipGating opt-out prop to Auth0ComponentProvider for permission gating Sep 29, 2026
@grandmaester grandmaester changed the title fix: add skipGating opt-out prop to Auth0ComponentProvider for permission gating fix(react, core): Add skipGating opt-out prop to Auth0ComponentProvider for permission gating Sep 29, 2026
@codecov-commenter

codecov-commenter commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.21%. Comparing base (4e2517b) to head (9e8e20e).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff            @@
##             main     #550    +/-   ##
========================================
  Coverage   91.20%   91.21%            
========================================
  Files         258      258            
  Lines       19870    19886    +16     
  Branches     3060     2406   -654     
========================================
+ Hits        18123    18139    +16     
  Misses       1747     1747            

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread packages/core/src/services/permissions/permission-map.ts Outdated
@grandmaester grandmaester changed the title fix(react, core): Add skipGating opt-out prop to Auth0ComponentProvider for permission gating fix(react, core): Add a new opt-out prop to Auth0ComponentProvider for skip permission gating Sep 29, 2026
@grandmaester
grandmaester merged commit fd04060 into main Sep 29, 2026
7 checks passed
@grandmaester
grandmaester deleted the fix/opt-out-flow-added-for-permissions-gating branch September 29, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants