You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
F27: Roles + scoped permissions — role model, flock-scoped workers, RBAC UI (builds on #73) #103
Spec §5.1–5.3. Grows the #73 Admin/Worker split into the real role model. #84 (magic strings: role/claim constants, typed SPA statuses) rides along — touching every gate is exactly when to de-string them.
Roles shipped now (spec §5.1)
Role
Gates
Owner
everything (today's Admin, renamed conceptually; existing Admin role remains the seed)
Manager
farm operations + inventory + reports + corrective actions — everything but user management and account-level config
Worker
production recording, restricted to assigned flocks (§5.3)
Sales
customers, orders, payments — no production writes, no expenses
Read-only
dashboards/reports/stock views only
Deferred with rationale (noted in GLOSSARY):
Vet/Consultant — there is no health/medication module to gate yet; an ungated role would be Read-only with a misleading name.
House-level scoping — houses are not entities yet (houseId is an opaque Guid on entries; spec itself defers real house management). Flock-level scoping ships now; the user_role_assignments shape carries the nullable house_id column per §5.2 so no schema churn later.
Scope
Domain/persistence: user_role_assignments per §5.2 (user, role, nullable farm/house/flock scope). Roles stay ASP.NET Identity roles (Owner=Admin seed, + Manager/Sales/ReadOnly); assignments add the scoping dimension.
Authz: policy layer maps role → allowed endpoint groups (replacing the binary AdminOnly on the non-money gates; money stays Owner/Manager). Worker flock-scope enforcement in daily-entry/water/feed record paths: assigned-flocks check → 403 with problem body.
API: user management grows role selection (all shipped roles) + flock assignment CRUD for workers (Owner only).
SPA: Users page — role picker + worker flock assignments; nav/screen gating per role (Sales sees sales+customers; Read-only sees dashboards/stock/reports).
Spec §5.1–5.3. Grows the #73 Admin/Worker split into the real role model. #84 (magic strings: role/claim constants, typed SPA statuses) rides along — touching every gate is exactly when to de-string them.
Roles shipped now (spec §5.1)
Deferred with rationale (noted in GLOSSARY):
houseIdis an opaque Guid on entries; spec itself defers real house management). Flock-level scoping ships now; theuser_role_assignmentsshape carries the nullablehouse_idcolumn per §5.2 so no schema churn later.Scope
user_role_assignmentsper §5.2 (user, role, nullable farm/house/flock scope). Roles stay ASP.NET Identity roles (Owner=Admin seed, + Manager/Sales/ReadOnly); assignments add the scoping dimension.Tests