Skip to content

Let ML data managers create and delete data exports - #1438

Open
mihow wants to merge 2 commits into
mainfrom
fix/ml-data-manager-can-export
Open

mihow wants to merge 2 commits into
mainfrom
fix/ml-data-manager-can-export

Conversation

@mihow

@mihow mihow commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

Summary

The ML data manager role is described as able to "manage jobs and export data", but it only held the permission to run an export job, not to create one. The exports page therefore offered ML data managers no way to start an export. This gives the role the same export permissions as the researcher role: create and delete data exports.

Existing projects pick up the change without a data migration, because the role permissions of every project are re-synced on post_migrate.

This is a small product decision as much as a fix, so it is worth a quick yes or no from whoever owns the roles: should ML data managers be able to export data themselves?

List of Changes

  1. ML data managers can create and delete data exports in their projects, like researchers. The MLDataManager role in ami/users/roles.py gains CREATE_DATA_EXPORT and DELETE_DATA_EXPORT.
  2. Tests check that an ML data manager is offered export creation, and that re-syncing roles grants it on projects that already exist.

How to test

python manage.py test ami.main ami.users (419 tests pass locally).

🤖 Generated with Claude Code

https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8

The ML data manager role is described as able to "manage jobs and export
data", but it only held the permission to run an export job, so the exports
page offered no way to start one. It now has the same export permissions as the
researcher role. Existing projects pick the grant up without a data migration,
because create_roles_for_project re-syncs every project's role permissions on
post_migrate.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C7Xf6VPbwWtTumhjjF15g8
Copilot AI lite review requested due to automatic review settings September 28, 2026 20:24
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 889f35fd-8da0-4ed9-93db-f32505694262

📥 Commits

Reviewing files that changed from the base of the PR and between 6740643 and ac3b8c0.

📒 Files selected for processing (2)
  • ami/main/tests.py
  • ami/users/roles.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for antenna-preview canceled.

Name Link
🔨 Latest commit ac3b8c0
🔍 Latest deploy log https://app.netlify.com/projects/antenna-preview/deploys/6abc65c6300d2a0008d1a16d

@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for antenna-ssec canceled.

Name Link
🔨 Latest commit ac3b8c0
🔍 Latest deploy log https://app.netlify.com/projects/antenna-ssec/deploys/6abc65c6459601000859602d

@mihow

mihow commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Claude says: The red "Backend Tests" check on this head is an infrastructure failure, not a code failure. The test job stops at "Run DB Migrations" before any test runs, because the registry now refuses anonymous pulls of the pinned MinIO images: minio-init Error unauthorized: access to the requested resource is not authorized. A rerun of the job gave the same error for the minio image, and docker manifest inspect returns the same refusal for both quay.io/minio/minio and quay.io/minio/mc from outside CI, so main is expected to fail the same way on its next run.

The image replacement is being handled in #1435. Its last run gets past the image pull, but 17 tests in two classes (the thumbnail views and the pipeline tests against the processing service) still error there. The same two classes error in a local stack when MinIO bucket setup or the processing service is missing, and pass once those are up.

Until CI is green again, the test evidence for this PR is a local run of the same CI compose stack, described in the PR description. Please treat the check as blocked on #1435 rather than as a review signal.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants