eduos-nav-entry-cross-role-surface-403
Solution written to /workspace/solution.md and verified against a faithful minimal reproduction.
No application repo was present in this environment (only /workspace/problem.json), so I reconstructed the exact architecture described — shared AuthLayout role→nav map, the student AiTutorPage fetching /ai-tutor/students/me/*, and an API requireRole guard simulator — and ran it with Vitest + React Testing Library.
Root cause: the shared nav config put { href: "/ai-tutor" } in the teacher array. That route is the student tutor client, whose endpoints are requireRole("student"). Teacher JWT → page → student-only endpoint → 403 → dead link.
Reproduced the bug before fixing:
FAIL ... does NOT show the student-only AI Tutor link to teachers
expected <a href="/ai-tutor">AI Tutor</a> to be null
Tests 2 failed | 3 passed
Root-cause probes also confirmed 403 for a teacher token and 200 for a student token on the same endpoint.
Applied Option A (remove the entry from the teacher array only) → 5/5 passed.
Also validated Option B (teacher page over /students/:id/indicators + session-summaries) → 7/7 passed.
The markdown contains the title, root-cause trace (href → page → endpoints → requireRole), the exact diff, the AuthLayout.test.tsx regression test, the Option B alternative, and a verification section with observed before/after output.
Note: because the real repository wasn't mounted, file/line references in the document are given as the exact snippets to locate and replace rather than absolute line numbers. Everything else (diff, test, commands, verified results) is directly usable.
# Evidence - Problem class: eduos-nav-entry-cross-role-surface-403 - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-14T08:52:24.247Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Shared AuthLayout nav array mapped teacher role to /ai-tutor, which is the STUDENT tutor client; its endpoints (/ai-tutor/students/me/*) are student-role-scoped so teacher JWT got 403 -> dead nav link + dead-end page. Diagnosis: map nav href to its page component, trace the page data-fetch endpoints to their API requireRole scopes. Fix (Option A, minimal): remove the student-only nav entry from the teacher array only; student surfaces untouched; added teacher-path regression test asserting the link is absent for role=teacher (AuthLayout.test.tsx). Option B alternative for retained discoverability: role-appropriate teacher page over existing teacher-scoped endpoints (students/:id/indicators, session-summaries). General rule: every nav entry must target a role-appropriate surface; assert per-role nav links in tests.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-nav-entry-cross-role-surface-403", "provider": "openrouter", "solved_at": "2026-09-14T08:52:24.248Z", "version": ""}