Skip to content

F19: Admin-gate corrective/destructive actions — stepping stone to full RBAC #73

Description

@mforce

Part of Phase 1.1 (epic #14). Owner request (2026-07-17): hide the advanced/corrective surface (editing entries, correcting purchases, voiding orders…) behind an admin role, ahead of the full house/flock-scoped RBAC line in the epic.

Context

  • Identity already seeds an Admin role (DatabaseSeeder) and JWTs can carry role claims — but no endpoint checks any role today; single login makes everything effectively admin.
  • F17: Edit submitted daily entries — lock job + manager adjust with lot/movement reconciliation #69 (edit submitted entries) already stipulates "admin-only until RBAC lands" with a TODO seam. This slice builds that seam properly and applies it across the board.
  • Full RBAC (workers scoped to houses/flocks, manager vs owner distinctions per spec §8.1/§10) stays a separate later slice; this one only distinguishes Admin from not-Admin.

Scope

Backend:

  • Role claims in the JWT (if not already emitted) + an AdminOnly authorization policy.
  • Apply to the corrective/destructive endpoints:
    • Sales: POST /sales/{id}/void
    • Inventory: POST /inventory/items/{id}/adjustments (Adjustment + Discard), item create + PUT (catalog definition/unit/cost are configuration, same as grades), activate/deactivate
    • Flocks: deplete, archive, reactivate; manual bird movements (Cull/Adjustment)
    • Grades: create/update/activate/deactivate
    • Daily entries: adjust/void when F17: Edit submitted daily entries — lock job + manager adjust with lot/movement reconciliation #69 lands (that slice inherits the policy)
    • Everyday capture (daily entry record/submit, purchases, feed usage, orders draft→confirm) stays open to any authenticated user — workers must be able to run the daily loop.
  • Minimal second user: a way to create a non-admin user (worker) so the gate is testable and useful — simplest possible: admin-only POST /users with email+password+role, no UI polish beyond a basic form. (Full user management UI belongs to the RBAC slice.)
  • 403 (not 404) for role-denied actions, with a clear message.

Exact endpoint list to be finalized at build time against the then-current surface — the principle: anything that undoes, corrects, or reconfigures is admin; anything that records the day's work is not.

SPA:

  • Role available from the token/account context; corrective controls (void, corrections, deplete/archive/reactivate, grade/item management, edit actions) hidden for non-admins — and the API still enforces regardless.
  • Help page (F18: In-app help — user guide + glossary in the SPA #71): note which actions are admin-only.

Tests: worker token → 403 on every gated endpoint, 2xx on the daily-loop ones; admin unchanged. Role claim round-trip.

Out of scope

  • House/flock-scoped permissions, manager tier, role management UI — the epic's full RBAC line.
  • Audit log (separate epic item).

Acceptance

  • A worker login can run the full daily loop (entry → submit, purchases, usage, draft order → confirm) but gets 403 + hidden UI for void/adjust/deplete/archive/reactivate/manage screens; admin experience unchanged.

Activity

  1. mforce commented on Jul 18, 2026

    @mforce
    OwnerAuthor

    Owner decision (2026-07-17): recording purchases stays open to regular users; editing purchases is admin-only. Note purchase-editing has exactly one form — the compensating Adjustment/Discard path (#66 part 2; lots and ledger rows are immutable) — and that path is in the admin-gated list. No open-to-worker edit route exists or should be added.

  2. mforce commented on Jul 18, 2026

    @mforce
    OwnerAuthor

    Full-surface sweep (2026-07-17) — additions and explicit calls beyond the original list:

    Add to admin-gated:

    • Flock update (PUT /flocks/{id}) — editing InitialCount silently changes derived CurrentBirds; that's a correction, not day work. Flock create too, for consistency (defining a batch = configuration, same reasoning as grades/items).
    • Water usage corrections (F16: Water usage tracking #67) — recording stays open; the issue's open design question ("edit with Version token vs delete-and-rerecord") resolves to whichever lands, it's admin-only, matching the purchases decision above.
    • CSV export / manual backup (epic item) — whole-dataset egress is admin.
    • Audit log UI (epic item) — admin, obviously.
    • Future expenses/payments (epic items) — same principle when they land: recording open, corrections/voids admin.

    Explicitly open to workers (decided, not omissions):

    • Cancel draft order — draft-only, touches no stock, part of the ordinary order workflow.
    • Customer create — new buyer walks in mid-sale; blocking on an admin would stall the sale. (No customer edit endpoint exists yet; when one lands, it can stay open — low blast radius — unless the owner prefers otherwise.)

    Flagged for owner decision at build time:

    • Reports: production reports (lay rates, mortality) open to workers; reports exposing money (feed cost/dozen, revenue, expenses) admin-only? Recommended split, cheap to implement per-report.

    Principle restated: records the day's work → open; undoes, corrects, configures, or exports → admin.

  3. mforce commented on Jul 18, 2026

    @mforce
    OwnerAuthor

    Owner decision (2026-07-17): reports split confirmed — production reports (lay rate, mortality, egg counts) open to workers; money reports (feed cost per dozen, revenue, expenses) admin-only. No open decisions remain on this issue; the endpoint list finalizes at build time against the then-current surface using the recorded principle.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions