* feat: let a workspace withdraw operator schedule and trigger writes
Operators can create, edit and delete schedules and triggers today through the
API, CLI and MCP, while the operator_settings flags beside them only hide those
pages. An admin who wants operators to see what is scheduled without letting
them change it cannot express that. Add manage_schedules and manage_triggers as
enforced settings, gated at the schedule handlers and at the generic TriggerCrud
routes so every trigger kind is covered by one check.
They name capabilities operators already hold, so they are granted unless
withdrawn, and absence has to mean "never configured" rather than a value. The
read coalesces to true; the update endpoint merges into the stored jsonb with
the two fields as Option<bool>, so an omitted key keeps what is stored.
operator_settings is git-synced as a whole object, so a settings file written
before these keys existed reaches the endpoint on every pull, and a serde or SQL
default of either polarity would turn that pull into a silent withdrawal or
restoration.
The rights are read through a per-process cache, so withdrawing one publishes a
notify_event that drops the entry on every replica.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dsf6VC4MVLisiEoeQkgbr4
* feat: enforce operator write rights on the router and in the UI
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: close the capture gap and gate the trigger editors' write actions
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: gate acl writes and the native trigger drawer behind manage rights
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: refuse operator writes with 403 and gate sharing at the drawer
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* perf: resolve identity in the operator write gate only for writes
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: gate the suspended-jobs actions and stop the route check refusing reads
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: explain the empty-state create button when operator writes are withdrawn
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix: audit operator settings changes and fold path writes into native rows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: open locked editors read-only and group the operator settings
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: skip email and azure lookups on editor open while triggers are locked
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* docs: state each operator-rights rationale once in comments
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: address CI review findings on operator write rights
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep capture move gated and skip it in the builders while locked
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep admin and operator exclusive when setting a workspace role
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* refactor: use the shared section component for operator settings groups
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>