Repository navigation
F19: Admin-gate corrective/destructive actions — stepping stone to full RBAC #73
Description
Activity
Owner decision (2026-07-17): recording purchases stays open to regular users; editing purchases is admin-only. Note purchase-editing has exactly one form — the compensating Adjustment/Discard path (#66 part 2; lots and ledger rows are immutable) — and that path is in the admin-gated list. No open-to-worker edit route exists or should be added.
Full-surface sweep (2026-07-17) — additions and explicit calls beyond the original list:
Add to admin-gated:
- Flock update (
PUT /flocks/{id}) — editingInitialCountsilently changes derived CurrentBirds; that's a correction, not day work. Flock create too, for consistency (defining a batch = configuration, same reasoning as grades/items). - Water usage corrections (F16: Water usage tracking #67) — recording stays open; the issue's open design question ("edit with Version token vs delete-and-rerecord") resolves to whichever lands, it's admin-only, matching the purchases decision above.
- CSV export / manual backup (epic item) — whole-dataset egress is admin.
- Audit log UI (epic item) — admin, obviously.
- Future expenses/payments (epic items) — same principle when they land: recording open, corrections/voids admin.
Explicitly open to workers (decided, not omissions):
- Cancel draft order — draft-only, touches no stock, part of the ordinary order workflow.
- Customer create — new buyer walks in mid-sale; blocking on an admin would stall the sale. (No customer edit endpoint exists yet; when one lands, it can stay open — low blast radius — unless the owner prefers otherwise.)
Flagged for owner decision at build time:
- Reports: production reports (lay rates, mortality) open to workers; reports exposing money (feed cost/dozen, revenue, expenses) admin-only? Recommended split, cheap to implement per-report.
Principle restated: records the day's work → open; undoes, corrects, configures, or exports → admin.
- Flock update (
Owner decision (2026-07-17): reports split confirmed — production reports (lay rate, mortality, egg counts) open to workers; money reports (feed cost per dozen, revenue, expenses) admin-only. No open decisions remain on this issue; the endpoint list finalizes at build time against the then-current surface using the recorded principle.
Part of Phase 1.1 (epic #14). Owner request (2026-07-17): hide the advanced/corrective surface (editing entries, correcting purchases, voiding orders…) behind an admin role, ahead of the full house/flock-scoped RBAC line in the epic.
Context
Adminrole (DatabaseSeeder) and JWTs can carry role claims — but no endpoint checks any role today; single login makes everything effectively admin.Scope
Backend:
AdminOnlyauthorization policy.POST /sales/{id}/voidPOST /inventory/items/{id}/adjustments(Adjustment + Discard), item create +PUT(catalog definition/unit/cost are configuration, same as grades), activate/deactivatePOST /userswith email+password+role, no UI polish beyond a basic form. (Full user management UI belongs to the RBAC slice.)Exact endpoint list to be finalized at build time against the then-current surface — the principle: anything that undoes, corrects, or reconfigures is admin; anything that records the day's work is not.
SPA:
Tests: worker token → 403 on every gated endpoint, 2xx on the daily-loop ones; admin unchanged. Role claim round-trip.
Out of scope
Acceptance