2026.09.64 — 2026-09-29
Added
Offer every plugin permission in the role editor, with a grouped picker, previews and a declaration check (778293bb)
The role editor, and the API-key permission picker, now list the permissions of every active plugin. They used to list only built-in modules' permissions, so a plugin's features could not be granted through the UI. A plugin's permissions appear under its name while it is active and leave the list when it is deactivated; roles that hold them keep them.
The role editor's permission picker is grouped by module or plugin and searchable. It shows each permission's description, marks the ones that act only at global scope, and selects or clears a whole group at once. Wildcards, and held permissions whose module or plugin is not active, are shown for what they are instead of being dropped on save.
Administration → Users offers each user's effective permissions: every permission per grant scope, the role it comes from and the wildcard it came through, with "No effect at this scope" where a global-only permission is granted on an environment or cluster (
GET /api/v1/users/{id}/effective-permissions,user:admin). Administration → Roles can compare two roles.A new
permissionscontributor in thestudiohealth group reports DEGRADED, without blocking startup, when a method guard or a plugin manifest names a permission that is not registered, when a permission has no description, or when a global-only permission is checked against a cluster.Plugin authors: a
permissionsentry inplugin.jsonmay now declare"globalOnly": truefor a permission its guards check without a cluster. The field is optional and defaults to false.