Skip to content

Create external user for collaborative, publications, use-cases - #224

Open
amit0539 wants to merge 23 commits into
devfrom
collaborative_user
Open

amit0539 wants to merge 23 commits into
devfrom
collaborative_user

Conversation

@amit0539

@amit0539 amit0539 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

amit0539 and others added 23 commits October 1, 2026 13:34
…tive model

- Remove organization ForeignKey from Collaborative model
- Add designation CharField to Collaborative model for user designation/title
- Update is_individual_collaborative property to return True for all collaboratives
- Update CollaborativeInput and CollaborativeInputPartial to exclude organization and include designation
- Update GraphQL schema to remove organization references in queries/mutations
- Update add_collaborative mutation to not use organization field
- Update update_collaborative mutation to handle designation field
- Update permission checks to pass None for organization parameter
- Update activity tracking to remove organization_id
- Add migration 0049 for schema changes

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- Add has_approved boolean field (default: False) to track approval status
- Add designation field to store user's title/position
- Set has_approved=True when creating external contributor via mutation
- Implement privacy masking in TypeExternalContributor GraphQL type:
  * Return 'Anonymous' for name if not approved
  * Never return email (always None for privacy)
  * Return organization/designation/bio only if approved
  * Return dates (created_at/updated_at) only if approved
- Update GraphQL schema to support designation and has_approved fields
- Add migration 0050 for schema changes

This ensures unapproved external contributors' personal data is protected.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- Remove organization CharField from ExternalContributor model
- Remove email field from GraphQL type (never exposed for privacy)
- Remove organization from input types and filter
- Always return created_at/updated_at dates for all users (approved or not)
- Update mutations to not handle organization field
- Add migration 0051 to remove organization from database

This simplifies the model and ensures consistent privacy handling.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- Add image field override in TypeExternalContributor
- Return None for image if user is not approved (has_approved=False)
- Only approved users can see the contributor's image
- Maintains privacy controls for personal data

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- Import external_contributor_schema
- Add Query to merged Query types
- Add Mutation to merged Mutation types
- This enables external contributor endpoints in GraphQL API

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Comprehensive test report documenting:
- Implementation details of privacy controls
- Field visibility matrix (approved vs anonymous users)
- GraphQL schema and mutations
- Test scenarios with expected responses
- Privacy requirements verification
- Database migrations
- Code quality checks

All privacy requirements implemented:
✅ Email never returned
✅ Personal data masked for unapproved users
✅ Dates always visible
✅ Organization field removed
✅ has_approved field added with default false
✅ Auto-approval on creation via mutation

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
- deleteExternalContributor: handle_django_errors=False (bool can't be in a union)
- image: use DjangoImageType instead of str
- created_at/updated_at: keep DateTime via auto fields
- Replace test report with results from a live run (17/17)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Require IsAuthenticated on all external contributor queries and mutations
- Search matches approved contributors by name only (never email, never unapproved)
- Remove name from ExternalContributorFilter

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Keep the search (name only, no email) and filter (id only) changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Email follows the same masking as other personal fields: returned when
has_approved is true, null otherwise.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Also record the raw API walkthrough and image checks in the test report.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add contributors and external_contributors to Publication, expose both
on TypePublication, and let updatePublication set external contributors
via externalContributorIds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add the 0048 migration that later migrations already depend on, the
random-name upload path for contributor images, and the contributor
service (email check, and merging a contributor into a user, which also
removes its image file and logs failures).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add external_contributors to UseCase, expose it on TypeUseCase, and let
updateUseCase set it via externalContributorIds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
When a user with a verified email is created or their email changes,
move a matching external contributor's credits to the user. Add a
merge_external_contributors command (with --dry-run) for existing users.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Resolve conflicts in publication update path:
- apply_publication_update: adopt dev's _UNSET sentinel semantics and
  published-row revalidation; carry over external_contributor_ids as an
  _UNSET-aware field set inside the same transaction.
- publication_schema: adopt dev's _update_kwargs helper; move
  external_contributor_ids from CreatePublicationInput (auto-merge
  misplacement) to UpdatePublicationInput with strawberry.UNSET default.
- Add 0052 merge migration joining 0048_publicationblock_title_description
  (dev) and 0051_remove_organization_from_external_contributor.

Note: externalContributorIds: null on update now clears contributors.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add IsAuthenticated to create, update, and delete external contributor
mutations and to searchExternalContributors. Single lookup and list
queries stay public.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@amit0539 amit0539 changed the title Collaborative user Create temporary external user for collaborative, publications, use-cases Oct 6, 2026
@amit0539 amit0539 changed the title Create temporary external user for collaborative, publications, use-cases Create external user for collaborative, publications, use-cases Oct 6, 2026
@amit0539

amit0539 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

External Contributors API.md
API Doc

@amit0539
amit0539 requested a review from anantjain341 October 6, 2026 07:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant