Add Roles & Admin/Super-Admin interface
Per organized-ideas.md §6: role assignment, account ban/unban/delete, and direct Admin/Super-Admin CRUD of public catalog entries outside the submission workflow. Backend: - list_users_for_admin(): Super-Admin-gated SECURITY DEFINER function joining profiles + auth.users (username, email, role, banned_until) — auth.users isn't exposed through PostgREST, so this is the only way to list accounts at all. - New Edge Function admin-user-action (ban/unban/delete), using @supabase/server's `auth: 'user'` mode to verify the caller's JWT, then Supabase Auth's Admin API for the actual mutation. This is deliberately an Edge Function rather than a Postgres function like everything else in this codebase: touching auth.users needs the Admin API, the stable documented interface, not a direct write to a schema Supabase manages internally. Self-action guard; verify_jwt = true at the gateway on top of the function's own JWT verification. - 5 new pgTAP tests (43/43 total) for list_users_for_admin (Super-Admin-only, even regular Admins get 42501). - CatalogRepository gains admin* methods (direct edit of a public port/cable/ device entry, plus adminUnpublish which flips is_public rather than deleting) — the update methods were already ownership-agnostic (RLS's is_admin() clause is what actually permits it), so these are thin aliases, not duplicated logic. Frontend: - authStore/AdminUserRepository: minimal role plumbing, shared UserRole type. - adminUserStore + AdminUsersModal: list/role-dropdown/ban/unban/delete, gated to Super Admin only via a new "Manage Users" TopBar button. - PortTypeManager/CableTypeManager/DevicePalette: built-in entries now show direct "Edit"/"Unpublish" for Admins (regular Admin included, per §6's capability table — not Super-Admin-exclusive) instead of "Suggest edit"; unpublish reuses the review-queue's impact-check RPC before confirming. - DeviceTemplateEditor gains an `adminMode` save path alongside its existing submissionMode/resubmitId ones. Verified: tsc -b and oxlint clean; supabase db reset + 43/43 pgTAP tests pass; confirmed both new privileged endpoints (the SQL function and the Edge Function) actually work through the real REST API via live curl calls — signup, email confirm, role promotion, ban/unban/delete round trips, self-action guard, non-super-admin rejection, and verify_jwt=true compatibility all exercised directly, not just asserted.
This commit is contained in:
@@ -3,6 +3,7 @@ import type { CableType, Catalog, DeviceTemplate, PortType } from '../domain/typ
|
||||
import type { CatalogRepository } from '../data/CatalogRepository'
|
||||
import { cableTypeToRow, deviceTemplateToRow, portTypeToRow } from '../data/catalogRowMapping'
|
||||
import { SupabaseCatalogRepository } from '../data/SupabaseCatalogRepository'
|
||||
import type { CatalogEntityType } from '../data/SubmissionRepository'
|
||||
import { useSubmissionStore } from './submissionStore'
|
||||
|
||||
const repository: CatalogRepository = new SupabaseCatalogRepository()
|
||||
@@ -51,6 +52,16 @@ interface CatalogStoreState {
|
||||
|
||||
hidePublicDeviceTemplate: (id: string) => void
|
||||
restorePublicDeviceTemplate: (id: string) => void
|
||||
|
||||
/** Admin/Super-Admin direct edit of an already-public entry, per
|
||||
* organized-ideas.md §6 — bypasses the submission/review workflow
|
||||
* entirely (RLS's is_admin() clause is what actually permits it). */
|
||||
adminUpdatePortType: (id: string, patch: Partial<Omit<PortType, 'id' | 'custom'>>) => Promise<void>
|
||||
adminUpdateCableType: (id: string, patch: Partial<Omit<CableType, 'id' | 'custom'>>) => Promise<void>
|
||||
adminUpdateDeviceTemplate: (id: string, patch: Partial<Omit<DeviceTemplate, 'id' | 'custom'>>) => Promise<void>
|
||||
/** Unpublishes (is_public -> false) rather than deletes — see
|
||||
* CatalogRepository.adminUnpublish. */
|
||||
adminUnpublish: (entityType: CatalogEntityType, id: string) => Promise<void>
|
||||
}
|
||||
|
||||
export const useCatalogStore = create<CatalogStoreState>((set, get) => ({
|
||||
@@ -140,4 +151,31 @@ export const useCatalogStore = create<CatalogStoreState>((set, get) => ({
|
||||
saveHiddenPublicIds(next)
|
||||
set({ hiddenPublicDeviceTemplateIds: next })
|
||||
},
|
||||
|
||||
// Re-fetch the whole catalog after each of these rather than patching
|
||||
// locally — device_template edits also touch device_template_ports, and
|
||||
// unpublish changes which rows even show up (custom flips true for the
|
||||
// Admin who did it, since is_admin() is the only thing still granting
|
||||
// them visibility — see adminUnpublish's own comment). Simplest correct
|
||||
// thing, and Admin actions here are infrequent enough that the extra
|
||||
// round trip doesn't matter.
|
||||
adminUpdatePortType: async (id, patch) => {
|
||||
await repository.adminUpdatePortType(id, patch)
|
||||
await get().loadCatalog()
|
||||
},
|
||||
|
||||
adminUpdateCableType: async (id, patch) => {
|
||||
await repository.adminUpdateCableType(id, patch)
|
||||
await get().loadCatalog()
|
||||
},
|
||||
|
||||
adminUpdateDeviceTemplate: async (id, patch) => {
|
||||
await repository.adminUpdateDeviceTemplate(id, patch)
|
||||
await get().loadCatalog()
|
||||
},
|
||||
|
||||
adminUnpublish: async (entityType, id) => {
|
||||
await repository.adminUnpublish(entityType, id)
|
||||
await get().loadCatalog()
|
||||
},
|
||||
}))
|
||||
|
||||
Reference in New Issue
Block a user