Skip to content

PM-4952: Allow PM project billing detail fallback#15

Merged
jmgasper merged 1 commit into
developfrom
PM-4952-2
May 4, 2026
Merged

PM-4952: Allow PM project billing detail fallback#15
jmgasper merged 1 commit into
developfrom
PM-4952-2

Conversation

@jmgasper

@jmgasper jmgasper commented May 4, 2026

Copy link
Copy Markdown
Contributor

What was broken

Project Manager users in Work could see a project billing account name and id, but the detail request used for the spend amount and info modal could still fail when the user did not have a direct BillingAccountAccess grant.

Root cause (if identifiable)

The earlier fix added a project-membership fallback, but the route did not initially allow plain Topcoder User tokens to reach it. The follow-up then required a management or copilot project-member role for every project-scoped caller, which did not match Projects API behavior for global Project Manager tokens that actively belong to the project.

What was changed

Allowed Topcoder User tokens through the billing-account detail route while keeping service-level authorization constrained to a direct BillingAccountAccess grant or project fallback. Project Manager and Topcoder Project Manager tokens can now use active membership on a project assigned to the billing account, while plain Topcoder User callers still need a management or copilot project-member role. Project-scoped callers continue to receive line items filtered by active project membership.

Authorization docs and Swagger text were updated for the adjusted fallback behavior.

Any added/updated tests

No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.

What was broken

Project Manager users in Work could see a project billing account name and id, but the detail request used for the spend amount and info modal could still fail when the user did not have a direct BillingAccountAccess grant.

Root cause (if identifiable)

The earlier fix added a project-membership fallback, but the route did not initially allow plain Topcoder User tokens to reach it. The follow-up then required a management or copilot project-member role for every project-scoped caller, which did not match Projects API behavior for global Project Manager tokens that actively belong to the project.

What was changed

Allowed Topcoder User tokens through the billing-account detail route while keeping service-level authorization constrained to a direct BillingAccountAccess grant or project fallback. Project Manager and Topcoder Project Manager tokens can now use active membership on a project assigned to the billing account, while plain Topcoder User callers still need a management or copilot project-member role. Project-scoped callers continue to receive line items filtered by active project membership.

Authorization docs and Swagger text were updated for the adjusted fallback behavior.

Any added/updated tests

No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.
@jmgasper
jmgasper merged commit 32e0867 into develop May 4, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant