/** A user's role — mirrors `profiles.role`'s check constraint. Defined here * (data layer) rather than in state/authStore.ts so both that store and * this repository share one definition without state importing from data * in the wrong direction. */ export type UserRole = 'regular' | 'admin' | 'super_admin' export interface AdminUserSummary { id: string username: string email: string role: UserRole /** Set (a future timestamp) while banned; undefined otherwise. */ bannedUntil?: string createdAt: string } /** Storage abstraction for Super-Admin user management (organized-ideas.md * §6's "CRUD user accounts"). Listing and role changes are plain * RLS/privileged-function reads and writes; ban/unban/delete go through * the admin-user-action Edge Function since those specifically need * Supabase Auth's Admin API — see that function's own header comment for * why this can't just be another SQL function like the rest. */ export interface AdminUserRepository { listUsers(): Promise updateRole(userId: string, role: UserRole): Promise /** Reversible — blocks login without touching the account's data. */ banUser(userId: string): Promise unbanUser(userId: string): Promise /** Irreversible — cascades to the user's profile, diagrams, and owned * private catalog entries via their existing foreign keys. */ deleteUser(userId: string): Promise }