tr
TryGhost
GitHub
Ghost
Workspace
GitHub
CI Pipeline Executions
Current execution
Succeeded
mike-gva-907
Runs and Agents
Configuration
Self-Healing CI
Project Graph
Circular Dependencies
Enterprise
Resource Usage
Analysis
Conformance
Enterprise
Runs
Current run
Succeeded
Tasks
Resource Usage
Insights
Compare tasks
Analytics
Sign in
Toggle sidebar
Added post export permissions to the backup integration ref https://linear.app/ghost/issue/GVA-907/ - Ghost(Pro) archives are gaining a `post-analytics.csv` alongside the existing `members.csv`, fetched from `GET /ghost/api/admin/posts/export/` with the `ghost-backup` integration key, and that endpoint is gated on `browse post` - There is no explicit export posts permission, so we use browse posts - exactly how `browse member` was added to this role in v5.121.0 to allow the members export - The role already holds `db: all`, and `posts` is in the database exporter's `TABLES_ALLOWLIST`, so the key can already read every post in full through the db export; this grants no data it could not already reach, just a narrower capability through a different door - It does open `/posts/` browse generally rather than only the export route, since permissions are per action type rather than per endpoint - Applied in fixtures and with a migration so both new and existing sites get the update, and mirrored into the test fixtures
nx run ghost-monorepo:lint:boundaries
⌘K
Succeeded
nx run ghost-monorepo:lint:boundaries
Click to copy
Linux
4 CPU cores
960514d8
30138
GitHub
Ghost
Workspace