Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Admin: policy-based authorization + member management endpoints (Phase 8.1, 8.2, 2.6)

オープン
#1 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
csharp, postgres

調査の方向性

まず、既存の IEndpointModule.MapEndpoints 規約と tests/CommunityPro.Tests/Members/MembersTestHarness.cs のハーネスを読みます。Identity/Members、リフレッシュトークン、プロフィール、検索に関する公開コントラクトとイベントパスを追跡してから、管理者グループとエンドポイントを実装します。xUnit のカバレッジを含め、ポリシー、エンドポイントの動作、無効化のフィルタリング、インデックスの削除を含むすべての受け入れ条件を満たせば完了です。

索引モデルが issue の本文から書いたものです。

説明

admin

Scope

Foundation for everything /admin/*: an admin authorization policy, plus the member-management endpoints. Also closes deferred item 2.6 (hide deactivated members) since deactivation is introduced here.

The admin role already exists in Identity (Phase 1). This ticket adds:

  1. An AdminPolicy (role admin, checked server-side on every request — DB-backed like ActiveMemberPolicy, not stale claims) and a reusable route-group pattern so other modules can mount /admin/* endpoints with the policy applied at group level.
  2. Member management endpoints (Identity/Members owned, /admin/* paths):
Method Path Notes
GET /admin/members paginated; filter by status; search by login/display name
POST /admin/members/{id}/activate manual activation — fallback for the orphan-PR edge case; runs the same pipeline as the webhook (publishes MemberActivated)
POST /admin/members/{id}/feature toggle MemberProfile.IsFeatured (drives spotlight)
POST /admin/members/{id}/deactivate sets Deactivated, revokes refresh-token families, publishes MemberDeactivated
  1. Deferred item 2.6: Members module subscribes to MemberDeactivated → profile is removed from the Meilisearch index and excluded from /members, /members/{id}, and /members/spotlight at query level (not UI level).

Error codes

admin.forbidden, members.not_found, members.already_active, members.already_deactivated

Acceptance criteria

  • Admin policy rejects non-admin active members (403) and is applied at the route-group level
  • Manual activation is idempotent and fires the same events as webhook activation
  • Deactivation revokes all refresh tokens for the user
  • Deactivated members disappear from list/detail/spotlight endpoints and from the search index (test each)
  • xUnit coverage for policy, each endpoint, and the MemberDeactivated handler
Conventions (project-wide, non-negotiable)
  • .NET 9, records for immutable shapes, file-scoped namespaces, primary constructors where they read well. Minimal-API endpoints grouped per module via IEndpointModule.MapEndpoints.
  • Result<T> (SharedKernel) instead of exception-driven control flow. Endpoint results map failures to ProblemDetails with the stable error codes listed above — the frontend keys off them.
  • Module owns its EF Core DbContext mapped to its own Postgres schema. Modules never reference each other's internals — cross-module needs go through a public contract interface or an in-process domain event (IEventPublisher).
  • All external calls (GitHub, Stripe, Brevo, Cloudinary, Meilisearch) behind interfaces owned by the consuming module.
  • Every list endpoint paginated (offset is fine). xUnit tests in tests/CommunityPro.Tests/<Module>/ following the existing harness patterns (see Members/MembersTestHarness.cs).
主要言語
C#
スター
0
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

環境構築

  • Dockerfile または Docker Compose ファイルあり
  • プルリクエストのテンプレートなし
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

CommunityPro/community-pro-api のほかの issue

CommunityPro/community-pro-api の issue をすべて見る

似ている issue

C# の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。