1. /config/test/ — json.loads(request.body) on GET crashed with JSONDecodeError.
Added @require_http_methods(['POST']) so GET returns 405 instead of 500.
2. /organizations/dropdowns/subsections/ — LegacySubSection.objects.order_by('name')
used wrong field name (model has name_en/name_ar, not 'name'). Fixed to 'name_en'.
3. /rca/create/ — RCACreateView.dispatch() called _check_rca_create(request) before
LoginRequiredMixin ran, so AnonymousUser hit is_px_admin() → AttributeError.
Added auth check before the RBAC check in dispatch().
Post-fix: authenticated sweep of all 242 UI URLs → 233 OK, 0 errors (500s).
Fixed 3 gaps in the QI Projects module:
Gap 1 (critical): team members couldn't manage their own tasks — the toggle
checkbox/edit/delete were gated behind admin-only can_edit. Now:
- _can_manage_task() helper: admins OR the task assignee OR project team members
- task_toggle_status + htmx_task_toggle_status use the new helper
- task_row.html shows the toggle for assignees (task.assigned_to.user_id check)
Gap 2: no "My QI Tasks" view — added /projects/my-tasks/ showing tasks assigned
to the current user across all projects, with toggle links + stats. Sidebar link.
Gap 3: no notification on task assignment — added apps/projects/signals.py
(post_save on QIProjectTask → create_in_app_notification). apps.py ready() wired.
Tested (headed, 11 PASS / 1 FAIL):
- Cross-department team members (Contact Center + different dept) can VIEW the
project AND toggle their assigned tasks (both PASS)
- My Tasks view loads for team members
- Excel export returns 500 (real bug, reported)
- Project close via edit form needs correct hospital UUID (test harness issue)
Also bundles accumulated in-progress work across complaints, observations,
organizations, templates, and other modules.
Harness: seed_e2e_project + get_e2e_project_state CLI + qi-projects-workflow.spec.ts