Implement read-only access to workspace pages#91305
Conversation
|
Hey, I noticed you changed If you want to automatically generate translations for other locales, an Expensify employee will have to:
Alternatively, if you are an external contributor, you can run the translation script locally with your own OpenAI API key. To learn more, try running: npx ts-node ./scripts/generateTranslations.ts --helpTypically, you'd want to translate only what you changed by running |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bddbc9abf
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
🚧 @flodnv has triggered a test Expensify/App build. You can view the workflow run here. |
|
🧪🧪 Use the links below to test this adhoc build on Android, iOS, and Web. Happy testing! 🧪🧪
|
|
🚀 Deployed to staging by https://github.com/flodnv in version: 9.3.91-0 🚀
Bundle Size Analysis (Sentry): |
Help site review for this PRYes — a help site update is needed. This PR expands the Auditor role from "view and comment on reports" to also viewing workspace settings pages in read-only mode (Overview, Members, More features, Categories, Tags, Taxes, Expensify Card, Company cards, etc.), with write actions hidden or disabled. The new in-product copy is "Your workspace role can view these settings, but can't edit them." The existing article Draft help site PR: #92315 What the docs PR changes
All UI labels were verified against @ShridharGoel, please review the linked help site PR and confirm it reflects the current behavior. Then mark the linked help site PR |
|
Deploy Blocker #92320 was identified to be related to this PR. |
|
Deploy Blocker #92322 was identified to be related to this PR. |
|
Deploy Blocker #92324 was identified to be related to this PR. |
|
Deploy Blocker #92325 was identified to be related to this PR. |
|
Deploy Blocker #92328 was identified to be related to this PR. |
|
Deploy Blocker #92336 was identified to be related to this PR. |
|
Deploy Blocker #92335 was identified to be related to this PR. |
|
Deploy Blocker #92354 was identified to be related to this PR. |
|
🚀 Deployed to staging by https://github.com/flodnv in version: 9.3.94-0 🚀
Bundle Size Analysis (Sentry): |
|
🤖 Docs review complete — changes required, draft PR already exists Yes, this PR requires a help site update. It expands the Auditor role: auditors can now open and view workspace settings pages (Overview, Members, More features, Categories, Tags, Taxes, Expensify Card, Company cards, and others they have read access to) in read-only mode, with write controls disabled or hidden. The existing article described Auditors only as able to "view and comment on reports," which is now incomplete. A draft docs PR already covers this update: #92315 What it changes (
All UI labels were verified against I did not open a new PR since the existing one already covers the required changes, has the @ShridharGoel, please review the linked help site PR and confirm it reflects the current behavior. Then mark the linked help site PR |
|
🚀 Deployed to production by https://github.com/luacmartins in version: 9.3.94-0 🚀
|
Explanation of Change
This adds the frontend support for workspace scoped roles.
Auditors can now open workspace pages they have read access to, including direct links. The workspace menu checks feature read permissions before showing each item. Page access wrappers use the new policy feature read check instead of requiring full admin access when a page passes
policyFeature.This also allows read-only access by disabling or hiding write-only controls on the More Features, Expensify Card, and Company Cards top-level pages.
Fixed Issues
$ #90497, #90498
PROPOSAL:
Tests
Offline tests
QA Steps
Same as tests.
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari
Screen.Recording.2026-05-22.at.1.28.50.AM.mov