Add Roles & Admin/Super-Admin interface
Per organized-ideas.md §6: role assignment, account ban/unban/delete, and direct Admin/Super-Admin CRUD of public catalog entries outside the submission workflow. Backend: - list_users_for_admin(): Super-Admin-gated SECURITY DEFINER function joining profiles + auth.users (username, email, role, banned_until) — auth.users isn't exposed through PostgREST, so this is the only way to list accounts at all. - New Edge Function admin-user-action (ban/unban/delete), using @supabase/server's `auth: 'user'` mode to verify the caller's JWT, then Supabase Auth's Admin API for the actual mutation. This is deliberately an Edge Function rather than a Postgres function like everything else in this codebase: touching auth.users needs the Admin API, the stable documented interface, not a direct write to a schema Supabase manages internally. Self-action guard; verify_jwt = true at the gateway on top of the function's own JWT verification. - 5 new pgTAP tests (43/43 total) for list_users_for_admin (Super-Admin-only, even regular Admins get 42501). - CatalogRepository gains admin* methods (direct edit of a public port/cable/ device entry, plus adminUnpublish which flips is_public rather than deleting) — the update methods were already ownership-agnostic (RLS's is_admin() clause is what actually permits it), so these are thin aliases, not duplicated logic. Frontend: - authStore/AdminUserRepository: minimal role plumbing, shared UserRole type. - adminUserStore + AdminUsersModal: list/role-dropdown/ban/unban/delete, gated to Super Admin only via a new "Manage Users" TopBar button. - PortTypeManager/CableTypeManager/DevicePalette: built-in entries now show direct "Edit"/"Unpublish" for Admins (regular Admin included, per §6's capability table — not Super-Admin-exclusive) instead of "Suggest edit"; unpublish reuses the review-queue's impact-check RPC before confirming. - DeviceTemplateEditor gains an `adminMode` save path alongside its existing submissionMode/resubmitId ones. Verified: tsc -b and oxlint clean; supabase db reset + 43/43 pgTAP tests pass; confirmed both new privileged endpoints (the SQL function and the Edge Function) actually work through the real REST API via live curl calls — signup, email confirm, role promotion, ban/unban/delete round trips, self-action guard, non-super-admin rejection, and verify_jwt=true compatibility all exercised directly, not just asserted.
This commit is contained in:
+42
-1
@@ -25,7 +25,7 @@ begin;
|
||||
|
||||
create extension if not exists pgtap with schema extensions;
|
||||
|
||||
select plan(38);
|
||||
select plan(43);
|
||||
|
||||
-- ----------------------------------------------------------------------
|
||||
-- Fixtures (as postgres — RLS does not apply)
|
||||
@@ -386,6 +386,47 @@ select is(
|
||||
'carol (admin) can look up the submitter''s username for a submission she can review'
|
||||
);
|
||||
|
||||
-- ----------------------------------------------------------------------
|
||||
-- Admin user listing (organized-ideas.md §6: "CRUD user accounts" is
|
||||
-- Super-Admin-only — even a regular Admin gets 42501 here, unlike the
|
||||
-- Admin-gated functions above).
|
||||
-- ----------------------------------------------------------------------
|
||||
|
||||
select set_config('request.jwt.claim.sub', '22222222-2222-2222-2222-222222222222', true);
|
||||
|
||||
select throws_ok(
|
||||
$$ select * from public.list_users_for_admin() $$,
|
||||
'42501'::char(5), null,
|
||||
'bob (regular user) cannot list users'
|
||||
);
|
||||
|
||||
select set_config('request.jwt.claim.sub', '33333333-3333-3333-3333-333333333333', true);
|
||||
|
||||
select throws_ok(
|
||||
$$ select * from public.list_users_for_admin() $$,
|
||||
'42501'::char(5), null,
|
||||
'carol (admin, not super admin) cannot list users'
|
||||
);
|
||||
|
||||
select set_config('request.jwt.claim.sub', '44444444-4444-4444-4444-444444444444', true);
|
||||
|
||||
select lives_ok(
|
||||
$$ select * from public.list_users_for_admin() $$,
|
||||
'dave (super admin) can list users'
|
||||
);
|
||||
|
||||
select is(
|
||||
(select role from public.list_users_for_admin() where username = 'alice'),
|
||||
'admin',
|
||||
'the listing reflects alice''s current role (promoted earlier in this test run)'
|
||||
);
|
||||
|
||||
select is(
|
||||
(select email from public.list_users_for_admin() where username = 'alice'),
|
||||
'alice@example.com',
|
||||
'the listing includes email, only readable via this Super-Admin-gated function (not directly through PostgREST)'
|
||||
);
|
||||
|
||||
select * from finish();
|
||||
|
||||
rollback;
|
||||
|
||||
Reference in New Issue
Block a user