Conversation
What was broken Project Manager users in Work could see a project billing account name and id, but the detail request used for the spend amount and info modal could still fail when the user did not have a direct BillingAccountAccess grant. Root cause (if identifiable) The earlier fix added a project-membership fallback, but the route did not initially allow plain Topcoder User tokens to reach it. The follow-up then required a management or copilot project-member role for every project-scoped caller, which did not match Projects API behavior for global Project Manager tokens that actively belong to the project. What was changed Allowed Topcoder User tokens through the billing-account detail route while keeping service-level authorization constrained to a direct BillingAccountAccess grant or project fallback. Project Manager and Topcoder Project Manager tokens can now use active membership on a project assigned to the billing account, while plain Topcoder User callers still need a management or copilot project-member role. Project-scoped callers continue to receive line items filtered by active project membership. Authorization docs and Swagger text were updated for the adjusted fallback behavior. Any added/updated tests No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was broken
Project Manager users in Work could see a project billing account name and id, but the detail request used for the spend amount and info modal could still fail when the user did not have a direct BillingAccountAccess grant.
Root cause (if identifiable)
The earlier fix added a project-membership fallback, but the route did not initially allow plain Topcoder User tokens to reach it. The follow-up then required a management or copilot project-member role for every project-scoped caller, which did not match Projects API behavior for global Project Manager tokens that actively belong to the project.
What was changed
Allowed Topcoder User tokens through the billing-account detail route while keeping service-level authorization constrained to a direct BillingAccountAccess grant or project fallback. Project Manager and Topcoder Project Manager tokens can now use active membership on a project assigned to the billing account, while plain Topcoder User callers still need a management or copilot project-member role. Project-scoped callers continue to receive line items filtered by active project membership.
Authorization docs and Swagger text were updated for the adjusted fallback behavior.
Any added/updated tests
No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.