Client-scoped read-only access to pal-e-docs project boards #13
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Type
Spike
Resolution
Option B — pal-enterprises proxy pattern. Decision documented in arch-multi-tenant. Follow-up feature ticket: #17.
Clients access their project board through pal-enterprises, which fetches data from pal-e-docs internally and renders a read-only view. Keycloak
project_sluguser attribute maps client to project. pal-e-docs stays internal.All success criteria met:
Scope Review: NEEDS_REFINEMENT
Review note:
review-1190-2026-05-09Issue body is well-structured and matches the spike template fully. Two traceability gaps prevent READY status:
story:client-portalis not listed inproject-pal-enterprisesuser-stories table. Create the entry (Role: Client, Metric: "Can view project board and status updates without seeing other clients' data").arch-multi-tenantarchitecture note exists in pal-e-docs. Create placeholder before spike begins -- the spike itself will populate it.pal-e-platform #357(NetworkPolicy) and#358(Keycloak infra).Scope Review: READY
Review note:
review-1190-2026-05-09(updated)Re-review after three refinements applied. All previous NEEDS_REFINEMENT issues resolved:
story:client-portaluser story entry verified in project-pal-enterprisesarch-multi-tenantarchitecture note exists as placeholderTicket is ready for next_up.