Deep links: link to plugin and admin list items #884

Open
opened 2026-10-02 17:33:18 +00:00 by kayg · 0 comments
Owner

Evidence

The plugin screen links to the Core and Optional groups, while plugin rows have only an internal rowId (apps/web/src/routes/settings/plugins/PluginsSection.svelte:134-161). Admin User rows have rowId={user.id} but no row link or Copy link action (apps/web/src/routes/settings/admin/UsersGroup.svelte:132-138). Open Invitation rows have rowId={invite.id} but no management link or Copy link action (apps/web/src/routes/settings/admin/InvitationsGroup.svelte:128-145). The invitation-creation screen copies a one-time credential URL; that is not a stable management link. docs/deep-links.md:108 records this gap.

Rule

CLAUDE.md, Deep links, requires every item to be deep-linkable and to use stable identities. DESIGN §33 covers Settings and admin routes.

Expected behavior

A User can copy a link to a plugin, admin User or open Invitation row. The link opens the correct Settings group and restores the selected row by its stable ID. Keep role and owner authorization checks. Never put a passkey or one-time invitation token in a management link.

Test idea

Copy each row link and open it in a fresh page. Verify the correct group and row are selected. Verify that an unauthorized User does not learn whether an admin record exists. For an Invitation, confirm that the management link does not contain or replace its one-time credential URL.

## Evidence The plugin screen links to the Core and Optional groups, while plugin rows have only an internal `rowId` (`apps/web/src/routes/settings/plugins/PluginsSection.svelte:134-161`). Admin User rows have `rowId={user.id}` but no row link or Copy link action (`apps/web/src/routes/settings/admin/UsersGroup.svelte:132-138`). Open Invitation rows have `rowId={invite.id}` but no management link or Copy link action (`apps/web/src/routes/settings/admin/InvitationsGroup.svelte:128-145`). The invitation-creation screen copies a one-time credential URL; that is not a stable management link. `docs/deep-links.md:108` records this gap. ## Rule CLAUDE.md, Deep links, requires every item to be deep-linkable and to use stable identities. DESIGN §33 covers Settings and admin routes. ## Expected behavior A User can copy a link to a plugin, admin User or open Invitation row. The link opens the correct Settings group and restores the selected row by its stable ID. Keep role and owner authorization checks. Never put a passkey or one-time invitation token in a management link. ## Test idea Copy each row link and open it in a fresh page. Verify the correct group and row are selected. Verify that an unauthorized User does not learn whether an admin record exists. For an Invitation, confirm that the management link does not contain or replace its one-time credential URL.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#884
No description provided.