feat(datatug-apps): read-only per-space raw-data viewer (transparency PoC) - #31
Merged
Merged
Conversation
… PoC)
Adds an "Explore my raw data" page rooted at /spaces/{spaceId} that lets a
signed-in user browse their own space's Firestore subtree as raw JSON,
read-only. Reuses the app's existing sneat-eur3-1 AngularFire auth and the
DatatugStoreFirestoreService doc/collection-streaming pattern, and relies
entirely on the existing spaces/{space} security rule for scoping — no new
backend, rules, or auth. First slice of the DataTug transparency-explorer
design (backstage/docs/roadmaps/datatug-transparency-explorer.md).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FV3pbooAc9UPpNdiaJuKve
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
First slice of the DataTug "explore your own raw data" transparency viewer
(see
backstage/docs/roadmaps/datatug-transparency-explorer.md, esp. §1.3and §6 "S — first high-signal slice"). Adds a read-only, per-space Firestore
viewer inside
datatug-apps, rooted at/spaces/{spaceId}instead ofDataTug's own
datatug_projects/{id}.SpaceExplorerPageComponent,libs/datatug/main/src/lib/pages/signed-in/space-explorer/), routed at/explore/:spaceId(auth-guarded viaSNEAT_AUTH_GUARDS, same as/my).Lets a signed-in user drill into their own space's raw Firestore subtree —
breadcrumb navigation, one document's fields rendered as raw JSON, or one
collection's documents listed — with shortcuts for the known
ext/{module}/{collection}convention (contactus,listus,calendarius,assetus,eventius, …) plus a free-text field for anyother collection name.
SpaceExplorerService(
libs/datatug/main/src/lib/services/repo/space-explorer.service.ts) —modeled on the existing
DatatugStoreFirestoreService.watchProjectItempattern (arbitrary-path
docData/collectionDatastreaming under thesigned-in user's own AngularFire session), but rooted at
spaces/{spaceId}and using only Firestore's read APIs. Read-only by construction — it
never imports/calls
setDoc/updateDoc/deleteDoc/addDoc, documentedwith an explicit banner comment.
sneat-eur3-1AngularFireauth wiring (
init-firebase.ts,environment.prod.ts) and the existingspaces/{space}/{document=**}Firestore security rule(
sneat-firebase/firebase/firestore.rules) — no backend, rules, or authchanges. Scoping ("only see your own space's data") is enforced
server-side by the rule, same as the rest of the app.
existing
/mypage. A real "my spaces" list isn't wired up indatatug-appsyet, so this PoC accepts aspaceIdas a route param —noted in-code as a follow-up.
Known limitation (documented in code)
The Firestore client SDK cannot enumerate a document's subcollections
(unlike the Admin SDK's
listCollections()) — that introspection isdeliberately not exposed client-side. So the tree browser can't show a
truly complete "here are all the child collections" list; it offers
well-known collection-name shortcuts (
space-explorer-known-collections.ts)plus a free-text field instead. Browsing a name that doesn't exist just
yields an empty list — expected, not an error.
How to run
Sign in, go to
/my, enter a space id you're a member of, click Explore —or navigate directly to
/explore/{spaceId}.Test plan
pnpm exec nx build datatug-app— passes (production build, bothdatatug-mainlib anddatatug-app)pnpm exec nx lint datatug-main/datatug-app— clean, noerrors/warnings
pnpm exec nx test datatug-main— all 84 existing test files / 108tests still pass (no new unit tests added for this PoC — flagged as a
follow-up)
sneat-eur3-1, navigate to a realspace, confirm raw docs render read-only, and confirm a non-member is
denied by the existing rule — not run in this pass (needs a real
signed-in session); build + lint + existing test suite is the
verification for this PoC.
Follow-ups (not in this PR)
space-membership source is reachable from
datatug-apps.@ingitdb/client-github(~/projects/ingitdb/ingitdb-ts/packages/client-github)— read-only
loadCollectionRecords/loadRecord/getContentsagainst onereal GitHub-vault repo, manual PAT first (see design doc §6 "S/M — GitHub/
inGitDB slice").
Firestore-vs-GitHub badge, once Track B's space→vault pointer exists (see
design doc §4, §1.7).
🤖 Generated with Claude Code
https://claude.ai/code/session_01FV3pbooAc9UPpNdiaJuKve