Ledger
WEB-216
Admin RBAC matrix e2e: 9 roles × 19 modules — sidebar shows exactly the permitted modules and every page renders or refuses accordingly (perms read from the database)
Evidence
From logs/evidence/WEB-216/. Click a thumbnail for the full image.
No evidence files in logs/evidence/WEB-216/.
Tests
pass admin e2e @rbac: 9 roles × 19 modules, sidebar exactly matches permissions, each page renders or refuses accordingly · 48.4 s · raw log
$ cd apps/admin && pnpm build >/dev/null 2>&1 && pnpm exec playwright test tests/e2e/rbac.spec.ts --project=desktop --workers=1 --reporter=lineNotes
2026-10-04 22:59 UTC · RBAC matrix (tests/e2e/rbac.spec.ts, tag @rbac): permissions read from admin.role_permissions; for owner, developer, qa, gm, moderator, support, marketing, analyst and read_only the sidebar links equal the modules their permissions allow, and all 19 module routes render (h1) or refuse (NoAccess) in agreement — 171 page checks, 0 disagreements. Mobile layout and a11y are covered per module by each spec's all-sizes test.
