Add Roles & Admin/Super-Admin interface

Per organized-ideas.md §6: role assignment, account ban/unban/delete, and
direct Admin/Super-Admin CRUD of public catalog entries outside the
submission workflow.

Backend:
- list_users_for_admin(): Super-Admin-gated SECURITY DEFINER function
  joining profiles + auth.users (username, email, role, banned_until) —
  auth.users isn't exposed through PostgREST, so this is the only way to
  list accounts at all.
- New Edge Function admin-user-action (ban/unban/delete), using
  @supabase/server's `auth: 'user'` mode to verify the caller's JWT, then
  Supabase Auth's Admin API for the actual mutation. This is deliberately
  an Edge Function rather than a Postgres function like everything else in
  this codebase: touching auth.users needs the Admin API, the stable
  documented interface, not a direct write to a schema Supabase manages
  internally. Self-action guard; verify_jwt = true at the gateway on top of
  the function's own JWT verification.
- 5 new pgTAP tests (43/43 total) for list_users_for_admin (Super-Admin-only,
  even regular Admins get 42501).
- CatalogRepository gains admin* methods (direct edit of a public port/cable/
  device entry, plus adminUnpublish which flips is_public rather than
  deleting) — the update methods were already ownership-agnostic (RLS's
  is_admin() clause is what actually permits it), so these are thin aliases,
  not duplicated logic.

Frontend:
- authStore/AdminUserRepository: minimal role plumbing, shared UserRole type.
- adminUserStore + AdminUsersModal: list/role-dropdown/ban/unban/delete,
  gated to Super Admin only via a new "Manage Users" TopBar button.
- PortTypeManager/CableTypeManager/DevicePalette: built-in entries now show
  direct "Edit"/"Unpublish" for Admins (regular Admin included, per §6's
  capability table — not Super-Admin-exclusive) instead of "Suggest edit";
  unpublish reuses the review-queue's impact-check RPC before confirming.
- DeviceTemplateEditor gains an `adminMode` save path alongside its existing
  submissionMode/resubmitId ones.

Verified: tsc -b and oxlint clean; supabase db reset + 43/43 pgTAP tests
pass; confirmed both new privileged endpoints (the SQL function and the
Edge Function) actually work through the real REST API via live curl
calls — signup, email confirm, role promotion, ban/unban/delete round
trips, self-action guard, non-super-admin rejection, and verify_jwt=true
compatibility all exercised directly, not just asserted.
This commit is contained in:
2026-09-08 16:01:01 -05:00
parent 1f8d49345e
commit 4c45b5afa7
21 changed files with 804 additions and 51 deletions
+21 -4
View File
@@ -1,3 +1,4 @@
import type { CatalogEntityType } from './SubmissionRepository'
import type { Catalog, CableType, DeviceCategoryDef, DeviceTemplate, PortType } from '../domain/types'
/**
@@ -7,10 +8,14 @@ import type { Catalog, CableType, DeviceCategoryDef, DeviceTemplate, PortType }
* entries plus their own private ones); RLS does that filtering server-side,
* so implementations don't need to filter client-side.
*
* Only covers the "read + manage your own private entries" surface for now.
* Submitting a private entry for public review/promotion is a separate,
* not-yet-built workflow (organized-ideas.md §3/§9) — these `add*`/`update*`
* methods always create or edit is_public = false rows you own.
* The `add*`/`update*` methods always create or edit an `is_public = false`
* row you own — that's the regular-user "own private catalog" surface.
* Getting an entry into the public catalog otherwise goes through the
* submission/review workflow (organized-ideas.md §3), except for the
* `admin*` methods below: per §6's capability table, an Admin/Super-Admin
* can also CRUD public entries directly, without a submission — those
* bypass ownership entirely (RLS's `is_admin()` clause is what actually
* allows it) and only ever touch already-public rows.
*/
export interface CatalogRepository {
/** Everything visible to the current user: public entries plus their own private ones. */
@@ -27,4 +32,16 @@ export interface CatalogRepository {
addDeviceTemplate(template: Omit<DeviceTemplate, 'id' | 'custom'>): Promise<DeviceTemplate>
updateDeviceTemplate(id: string, patch: Partial<Omit<DeviceTemplate, 'id' | 'custom'>>): Promise<void>
removeDeviceTemplate(id: string): Promise<void>
/** Admin/Super-Admin direct edit of an already-public port/cable/device
* entry — same underlying write as approving a submission, minus the
* submission. */
adminUpdatePortType(id: string, patch: Partial<Omit<PortType, 'id' | 'custom'>>): Promise<void>
adminUpdateCableType(id: string, patch: Partial<Omit<CableType, 'id' | 'custom'>>): Promise<void>
adminUpdateDeviceTemplate(id: string, patch: Partial<Omit<DeviceTemplate, 'id' | 'custom'>>): Promise<void>
/** Unpublishes a public entry (is_public -> false) rather than deleting
* it — organized-ideas.md §3's "public catalog entries are never hard-
* deleted, only hidden/unpublished". Existing diagrams that reference it
* by id are unaffected; it just stops being offered for new use. */
adminUnpublish(entityType: CatalogEntityType, id: string): Promise<void>
}