Conversation
What was broken Project Managers who could access a Work project could still receive a not found response from GET /billing-accounts/:billingAccountId when the billing account was not present in BillingAccountAccess. Root cause (if identifiable) The billing-account detail endpoint only checked legacy billing-account access grants for restricted Project Manager reads. Work project pages rely on project membership and the project's billingAccountId, so missing imported legacy grants blocked project-level billing-account access. What was changed Added a Projects DB membership fallback for restricted Project Manager detail reads. When no direct billing-account grant exists, the API checks for a non-deleted project with the requested billingAccountId and a non-deleted project_members row for the caller before loading details. Updated Swagger and README authorization documentation to describe the project-membership fallback. Any added/updated tests No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.
PM-4952: Allow project managers to open project billing accounts
What was broken Project Manager users in Work could see a project billing account name and id, but the detail request used for the spend amount and info modal could still fail when the user did not have a direct BillingAccountAccess grant. Root cause (if identifiable) The earlier fix added a project-membership fallback, but the route did not initially allow plain Topcoder User tokens to reach it. The follow-up then required a management or copilot project-member role for every project-scoped caller, which did not match Projects API behavior for global Project Manager tokens that actively belong to the project. What was changed Allowed Topcoder User tokens through the billing-account detail route while keeping service-level authorization constrained to a direct BillingAccountAccess grant or project fallback. Project Manager and Topcoder Project Manager tokens can now use active membership on a project assigned to the billing account, while plain Topcoder User callers still need a management or copilot project-member role. Project-scoped callers continue to receive line items filtered by active project membership. Authorization docs and Swagger text were updated for the adjusted fallback behavior. Any added/updated tests No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.
PM-4952: Allow PM project billing detail fallback
What was broken A Project Manager token could still get 404 from GET /billing-accounts/:billingAccountId for a billing account that exists and is assigned to a Work project. Administrators could read the same billing account. Root cause (if identifiable) The previous billing-account fallback still required project membership for global Project Manager callers. Projects API grants billing-account detail access to the global Project Manager role by project assignment, so billing-accounts-api-v6 was stricter than the project permission model. What was changed Global Project Manager and Topcoder Project Manager callers can now use a non-deleted project assignment for billing-account detail fallback access when there is no direct BillingAccountAccess grant. Plain Topcoder User callers still need active project membership with an allowed management or copilot project role. Authorization documentation was updated to match the behavior. Any added/updated tests No automated tests were added because billing-accounts-api-v6 does not define a test script. Validation was performed with pnpm lint and pnpm build; pnpm test reports that the test script is missing.
PM-4952: Allow PM billing detail by project assignment
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prod release for BA visiblity
https://topcoder.atlassian.net/browse/PM-4943
https://topcoder.atlassian.net/browse/PM-4952