feature: a minimal implementation of staff management is done.
This commit is contained in:
@@ -45,10 +45,10 @@ async function main() {
|
|||||||
// Create plans
|
// Create plans
|
||||||
const plans = [
|
const plans = [
|
||||||
{ name: 'trial', maxUsers: 5, price: 0, features: {} },
|
{ name: 'trial', maxUsers: 5, price: 0, features: {} },
|
||||||
{ name: 'Small', maxUsers: 5, price: 79, features: {} },
|
{ name: 'Small', maxUsers: 5, price: 150, features: {} },
|
||||||
{ name: 'Medium', maxUsers: 10, price: 129, features: {} },
|
{ name: 'Medium', maxUsers: 10, price: 250, features: {} },
|
||||||
{ name: 'Large', maxUsers: 15, price: 179, features: {} },
|
{ name: 'Large', maxUsers: 15, price: 400, features: {} },
|
||||||
{ name: 'Enterprise', maxUsers: 999999, price: 299, features: {} },
|
{ name: 'Enterprise', maxUsers: 999999, price: 1000, features: {} },
|
||||||
];
|
];
|
||||||
|
|
||||||
for (const plan of plans) {
|
for (const plan of plans) {
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ import { AppService } from './app.service';
|
|||||||
import { AdminModule } from './admin/admin.module';
|
import { AdminModule } from './admin/admin.module';
|
||||||
import { PrismaModule } from '../prisma/prisma.module'; // ✅
|
import { PrismaModule } from '../prisma/prisma.module'; // ✅
|
||||||
import { PatientsModule } from './modules/patients/patients.module';
|
import { PatientsModule } from './modules/patients/patients.module';
|
||||||
|
import { StaffModule } from './modules/staff/staff.module';
|
||||||
|
|
||||||
@Module({
|
@Module({
|
||||||
imports: [
|
imports: [
|
||||||
@@ -17,6 +18,7 @@ import { PatientsModule } from './modules/patients/patients.module';
|
|||||||
PrismaModule, // ✅ ADD THIS
|
PrismaModule, // ✅ ADD THIS
|
||||||
AuthModule,
|
AuthModule,
|
||||||
PatientsModule,
|
PatientsModule,
|
||||||
|
StaffModule,
|
||||||
AdminModule.forRoot(),
|
AdminModule.forRoot(),
|
||||||
],
|
],
|
||||||
controllers: [AppController],
|
controllers: [AppController],
|
||||||
|
|||||||
37
backend/src/common/permissions.spec.ts
Normal file
37
backend/src/common/permissions.spec.ts
Normal file
@@ -0,0 +1,37 @@
|
|||||||
|
import { isUnlimitedSeats, normalizeTabPermissions, SEAT_UNLIMITED_THRESHOLD } from './permissions';
|
||||||
|
|
||||||
|
describe('normalizeTabPermissions', () => {
|
||||||
|
it('adds READ when EDIT is present', () => {
|
||||||
|
expect(normalizeTabPermissions(['TAB_PATIENTS_EDIT'])).toEqual([
|
||||||
|
'TAB_PATIENTS_READ',
|
||||||
|
'TAB_PATIENTS_EDIT',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('dedupes and sorts', () => {
|
||||||
|
expect(
|
||||||
|
normalizeTabPermissions([
|
||||||
|
'TAB_TODAY_READ',
|
||||||
|
'TAB_TODAY_EDIT',
|
||||||
|
'TAB_TODAY_READ',
|
||||||
|
'bogus',
|
||||||
|
]),
|
||||||
|
).toEqual(['TAB_TODAY_READ', 'TAB_TODAY_EDIT']);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('accepts empty array', () => {
|
||||||
|
expect(normalizeTabPermissions([])).toEqual([]);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('isUnlimitedSeats', () => {
|
||||||
|
it('treats sentinel as unlimited', () => {
|
||||||
|
expect(isUnlimitedSeats(SEAT_UNLIMITED_THRESHOLD)).toBe(true);
|
||||||
|
expect(isUnlimitedSeats(SEAT_UNLIMITED_THRESHOLD + 1)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('treats normal caps as limited', () => {
|
||||||
|
expect(isUnlimitedSeats(5)).toBe(false);
|
||||||
|
expect(isUnlimitedSeats(15)).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
57
backend/src/common/permissions.ts
Normal file
57
backend/src/common/permissions.ts
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
/** Tab permissions — keep in sync with prisma seed and AuthService ALL_PERMISSIONS */
|
||||||
|
export const ALL_TAB_PERMISSIONS = [
|
||||||
|
'TAB_TODAY_READ',
|
||||||
|
'TAB_TODAY_EDIT',
|
||||||
|
'TAB_PATIENTS_READ',
|
||||||
|
'TAB_PATIENTS_EDIT',
|
||||||
|
'TAB_APPOINTMENTS_READ',
|
||||||
|
'TAB_APPOINTMENTS_EDIT',
|
||||||
|
'TAB_STAFF_READ',
|
||||||
|
'TAB_STAFF_EDIT',
|
||||||
|
'TAB_LAB_READ',
|
||||||
|
'TAB_LAB_EDIT',
|
||||||
|
'TAB_BILLING_READ',
|
||||||
|
'TAB_BILLING_EDIT',
|
||||||
|
'TAB_REPORTS_READ',
|
||||||
|
'TAB_REPORTS_EDIT',
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
export type TabPermission = (typeof ALL_TAB_PERMISSIONS)[number];
|
||||||
|
|
||||||
|
const ALL_TAB_SET = new Set<string>(ALL_TAB_PERMISSIONS);
|
||||||
|
const TAB_ORDER_INDEX = new Map<string, number>(
|
||||||
|
ALL_TAB_PERMISSIONS.map((p, i) => [p, i]),
|
||||||
|
);
|
||||||
|
|
||||||
|
/** Enterprise / unlimited seat plans use this sentinel in seed data */
|
||||||
|
export const SEAT_UNLIMITED_THRESHOLD = 999999;
|
||||||
|
|
||||||
|
export function isUnlimitedSeats(maxUsers: number): boolean {
|
||||||
|
return maxUsers >= SEAT_UNLIMITED_THRESHOLD;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** EDIT implies READ for the same feature tab */
|
||||||
|
const EDIT_TO_READ: Record<string, string> = {
|
||||||
|
TAB_TODAY_EDIT: 'TAB_TODAY_READ',
|
||||||
|
TAB_PATIENTS_EDIT: 'TAB_PATIENTS_READ',
|
||||||
|
TAB_APPOINTMENTS_EDIT: 'TAB_APPOINTMENTS_READ',
|
||||||
|
TAB_STAFF_EDIT: 'TAB_STAFF_READ',
|
||||||
|
TAB_LAB_EDIT: 'TAB_LAB_READ',
|
||||||
|
TAB_BILLING_EDIT: 'TAB_BILLING_READ',
|
||||||
|
TAB_REPORTS_EDIT: 'TAB_REPORTS_READ',
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dedupe, drop unknown strings, and add implied READ permissions for each EDIT.
|
||||||
|
*/
|
||||||
|
export function normalizeTabPermissions(names: string[]): string[] {
|
||||||
|
const out = new Set<string>();
|
||||||
|
for (const raw of names) {
|
||||||
|
const n = typeof raw === 'string' ? raw.trim() : '';
|
||||||
|
if (!n || !ALL_TAB_SET.has(n)) continue;
|
||||||
|
out.add(n);
|
||||||
|
const read = EDIT_TO_READ[n];
|
||||||
|
if (read) out.add(read);
|
||||||
|
}
|
||||||
|
return [...out].sort((a, b) => (TAB_ORDER_INDEX.get(a) ?? 0) - (TAB_ORDER_INDEX.get(b) ?? 0));
|
||||||
|
}
|
||||||
@@ -751,6 +751,7 @@ export class AuthService {
|
|||||||
name: membership.organization.name,
|
name: membership.organization.name,
|
||||||
type: membership.organization.type.name,
|
type: membership.organization.type.name,
|
||||||
isOwner: membership.isOwner,
|
isOwner: membership.isOwner,
|
||||||
|
permissions,
|
||||||
plan: membership.organization.plan
|
plan: membership.organization.plan
|
||||||
? {
|
? {
|
||||||
name: membership.organization.plan.name,
|
name: membership.organization.plan.name,
|
||||||
@@ -758,7 +759,6 @@ export class AuthService {
|
|||||||
}
|
}
|
||||||
: undefined,
|
: undefined,
|
||||||
},
|
},
|
||||||
permissions,
|
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
15
backend/src/modules/staff/dto/invite-staff.dto.ts
Normal file
15
backend/src/modules/staff/dto/invite-staff.dto.ts
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
import { IsArray, IsEmail, IsString, MinLength } from 'class-validator';
|
||||||
|
|
||||||
|
export class InviteStaffDto {
|
||||||
|
@IsEmail()
|
||||||
|
email: string;
|
||||||
|
|
||||||
|
@IsString()
|
||||||
|
@MinLength(1)
|
||||||
|
name: string;
|
||||||
|
|
||||||
|
/** TAB_* permission names; EDIT implies READ after normalization. */
|
||||||
|
@IsArray()
|
||||||
|
@IsString({ each: true })
|
||||||
|
permissionNames: string[];
|
||||||
|
}
|
||||||
13
backend/src/modules/staff/dto/update-staff-member.dto.ts
Normal file
13
backend/src/modules/staff/dto/update-staff-member.dto.ts
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
import { IsArray, IsOptional, IsString, MinLength } from 'class-validator';
|
||||||
|
|
||||||
|
export class UpdateStaffMemberDto {
|
||||||
|
@IsOptional()
|
||||||
|
@IsString()
|
||||||
|
@MinLength(1)
|
||||||
|
name?: string;
|
||||||
|
|
||||||
|
@IsOptional()
|
||||||
|
@IsArray()
|
||||||
|
@IsString({ each: true })
|
||||||
|
permissionNames?: string[];
|
||||||
|
}
|
||||||
62
backend/src/modules/staff/staff.controller.ts
Normal file
62
backend/src/modules/staff/staff.controller.ts
Normal file
@@ -0,0 +1,62 @@
|
|||||||
|
import {
|
||||||
|
Body,
|
||||||
|
Controller,
|
||||||
|
Delete,
|
||||||
|
Get,
|
||||||
|
Param,
|
||||||
|
Patch,
|
||||||
|
Post,
|
||||||
|
Req,
|
||||||
|
UseGuards,
|
||||||
|
} from '@nestjs/common';
|
||||||
|
import { ApiBearerAuth, ApiOperation, ApiTags } from '@nestjs/swagger';
|
||||||
|
import { JwtAuthGuard } from '../auth/guards/jwt-auth.guard';
|
||||||
|
import { InviteStaffDto } from './dto/invite-staff.dto';
|
||||||
|
import { UpdateStaffMemberDto } from './dto/update-staff-member.dto';
|
||||||
|
import { StaffService } from './staff.service';
|
||||||
|
|
||||||
|
@ApiTags('staff')
|
||||||
|
@ApiBearerAuth('JWT-auth')
|
||||||
|
@UseGuards(JwtAuthGuard)
|
||||||
|
@Controller('staff')
|
||||||
|
export class StaffController {
|
||||||
|
constructor(private readonly staffService: StaffService) {}
|
||||||
|
|
||||||
|
@Get()
|
||||||
|
@ApiOperation({ summary: 'List organization members (requires TAB_STAFF_READ or owner)' })
|
||||||
|
list(@Req() req: { user: { id: string; organizationId?: string } }) {
|
||||||
|
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||||
|
return this.staffService.list(req.user.id, organizationId);
|
||||||
|
}
|
||||||
|
|
||||||
|
@Post('invite')
|
||||||
|
@ApiOperation({ summary: 'Invite staff (requires TAB_STAFF_EDIT or owner)' })
|
||||||
|
invite(
|
||||||
|
@Req() req: { user: { id: string; organizationId?: string } },
|
||||||
|
@Body() dto: InviteStaffDto,
|
||||||
|
) {
|
||||||
|
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||||
|
return this.staffService.invite(req.user.id, organizationId, dto);
|
||||||
|
}
|
||||||
|
|
||||||
|
@Patch('members/:membershipId')
|
||||||
|
@ApiOperation({ summary: 'Update staff member name and/or permissions' })
|
||||||
|
updateMember(
|
||||||
|
@Req() req: { user: { id: string; organizationId?: string } },
|
||||||
|
@Param('membershipId') membershipId: string,
|
||||||
|
@Body() dto: UpdateStaffMemberDto,
|
||||||
|
) {
|
||||||
|
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||||
|
return this.staffService.updateMember(req.user.id, organizationId, membershipId, dto);
|
||||||
|
}
|
||||||
|
|
||||||
|
@Delete('members/:membershipId')
|
||||||
|
@ApiOperation({ summary: 'Remove staff member from organization' })
|
||||||
|
removeMember(
|
||||||
|
@Req() req: { user: { id: string; organizationId?: string } },
|
||||||
|
@Param('membershipId') membershipId: string,
|
||||||
|
) {
|
||||||
|
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||||
|
return this.staffService.removeMember(req.user.id, organizationId, membershipId);
|
||||||
|
}
|
||||||
|
}
|
||||||
10
backend/src/modules/staff/staff.module.ts
Normal file
10
backend/src/modules/staff/staff.module.ts
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
import { Module } from '@nestjs/common';
|
||||||
|
import { PrismaService } from '../../../prisma/prisma.service';
|
||||||
|
import { StaffController } from './staff.controller';
|
||||||
|
import { StaffService } from './staff.service';
|
||||||
|
|
||||||
|
@Module({
|
||||||
|
controllers: [StaffController],
|
||||||
|
providers: [StaffService, PrismaService],
|
||||||
|
})
|
||||||
|
export class StaffModule {}
|
||||||
288
backend/src/modules/staff/staff.service.ts
Normal file
288
backend/src/modules/staff/staff.service.ts
Normal file
@@ -0,0 +1,288 @@
|
|||||||
|
import {
|
||||||
|
BadRequestException,
|
||||||
|
ConflictException,
|
||||||
|
ForbiddenException,
|
||||||
|
Injectable,
|
||||||
|
NotFoundException,
|
||||||
|
} from '@nestjs/common';
|
||||||
|
import * as bcrypt from 'bcrypt';
|
||||||
|
import { randomBytes } from 'crypto';
|
||||||
|
import { PrismaService } from '../../../prisma/prisma.service';
|
||||||
|
import { isUnlimitedSeats, normalizeTabPermissions } from '../../common/permissions';
|
||||||
|
import { InviteStaffDto } from './dto/invite-staff.dto';
|
||||||
|
import { UpdateStaffMemberDto } from './dto/update-staff-member.dto';
|
||||||
|
|
||||||
|
@Injectable()
|
||||||
|
export class StaffService {
|
||||||
|
constructor(private readonly prisma: PrismaService) {}
|
||||||
|
|
||||||
|
getOrganizationIdFromUser(user: { organizationId?: string }) {
|
||||||
|
if (!user?.organizationId) {
|
||||||
|
throw new BadRequestException('Organization is not selected');
|
||||||
|
}
|
||||||
|
return user.organizationId;
|
||||||
|
}
|
||||||
|
|
||||||
|
async list(userId: string, organizationId: string) {
|
||||||
|
const actor = await this.getActorMembership(userId, organizationId);
|
||||||
|
if (!actor || !this.canViewStaff(actor)) {
|
||||||
|
throw new ForbiddenException('You do not have access to staff management');
|
||||||
|
}
|
||||||
|
|
||||||
|
const org = await this.prisma.organization.findUnique({
|
||||||
|
where: { id: organizationId },
|
||||||
|
include: { plan: true },
|
||||||
|
});
|
||||||
|
if (!org) {
|
||||||
|
throw new NotFoundException('Organization not found');
|
||||||
|
}
|
||||||
|
|
||||||
|
const [members, seatsUsed] = await Promise.all([
|
||||||
|
this.prisma.membership.findMany({
|
||||||
|
where: { organizationId },
|
||||||
|
include: {
|
||||||
|
user: { select: { id: true, email: true, name: true } },
|
||||||
|
permissions: { include: { permission: true } },
|
||||||
|
},
|
||||||
|
orderBy: [{ isOwner: 'desc' }, { createdAt: 'asc' }],
|
||||||
|
}),
|
||||||
|
this.prisma.membership.count({ where: { organizationId } }),
|
||||||
|
]);
|
||||||
|
|
||||||
|
const maxUsers = org.plan.maxUsers;
|
||||||
|
const unlimited = isUnlimitedSeats(maxUsers);
|
||||||
|
|
||||||
|
return {
|
||||||
|
success: true,
|
||||||
|
data: {
|
||||||
|
members: members.map((m) => ({
|
||||||
|
id: m.id,
|
||||||
|
userId: m.user.id,
|
||||||
|
email: m.user.email,
|
||||||
|
name: m.user.name,
|
||||||
|
isOwner: m.isOwner,
|
||||||
|
permissions: m.isOwner
|
||||||
|
? null
|
||||||
|
: m.permissions.map((p) => p.permission.name),
|
||||||
|
})),
|
||||||
|
seats: {
|
||||||
|
used: seatsUsed,
|
||||||
|
limit: unlimited ? null : maxUsers,
|
||||||
|
unlimited,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async invite(userId: string, organizationId: string, dto: InviteStaffDto) {
|
||||||
|
const actor = await this.getActorMembership(userId, organizationId);
|
||||||
|
if (!actor || !this.canEditStaff(actor)) {
|
||||||
|
throw new ForbiddenException('You cannot invite or manage staff');
|
||||||
|
}
|
||||||
|
|
||||||
|
const email = dto.email.trim().toLowerCase();
|
||||||
|
const normalizedPerms = normalizeTabPermissions(dto.permissionNames);
|
||||||
|
|
||||||
|
const permissionRows = await this.prisma.permission.findMany({
|
||||||
|
where: { name: { in: normalizedPerms } },
|
||||||
|
select: { id: true, name: true },
|
||||||
|
});
|
||||||
|
if (permissionRows.length !== normalizedPerms.length) {
|
||||||
|
const ok = new Set(permissionRows.map((p) => p.name));
|
||||||
|
const missing = normalizedPerms.filter((n) => !ok.has(n));
|
||||||
|
throw new BadRequestException(`Unknown or invalid permissions: ${missing.join(', ')}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
let temporaryPassword: string | null = null;
|
||||||
|
|
||||||
|
const result = await this.prisma.$transaction(async (tx) => {
|
||||||
|
const org = await tx.organization.findUnique({
|
||||||
|
where: { id: organizationId },
|
||||||
|
include: { plan: true },
|
||||||
|
});
|
||||||
|
if (!org) {
|
||||||
|
throw new NotFoundException('Organization not found');
|
||||||
|
}
|
||||||
|
|
||||||
|
const maxUsers = org.plan.maxUsers;
|
||||||
|
const seatsUsed = await tx.membership.count({ where: { organizationId } });
|
||||||
|
if (!isUnlimitedSeats(maxUsers) && seatsUsed >= maxUsers) {
|
||||||
|
throw new BadRequestException(
|
||||||
|
`Your plan allows ${maxUsers} team members. Remove a member or upgrade to add more.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const existingUser = await tx.user.findUnique({ where: { email } });
|
||||||
|
let targetUserId: string;
|
||||||
|
|
||||||
|
if (existingUser) {
|
||||||
|
if (existingUser.id === org.ownerId) {
|
||||||
|
throw new BadRequestException('Organization owner is already a member');
|
||||||
|
}
|
||||||
|
const dup = await tx.membership.findUnique({
|
||||||
|
where: {
|
||||||
|
userId_organizationId: {
|
||||||
|
userId: existingUser.id,
|
||||||
|
organizationId,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
if (dup) {
|
||||||
|
throw new ConflictException('This user is already a member of this organization');
|
||||||
|
}
|
||||||
|
targetUserId = existingUser.id;
|
||||||
|
} else {
|
||||||
|
temporaryPassword = randomBytes(18).toString('base64url').slice(0, 20);
|
||||||
|
const passwordHash = await bcrypt.hash(temporaryPassword, 10);
|
||||||
|
const created = await tx.user.create({
|
||||||
|
data: {
|
||||||
|
email,
|
||||||
|
name: dto.name.trim(),
|
||||||
|
passwordHash,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
targetUserId = created.id;
|
||||||
|
}
|
||||||
|
|
||||||
|
const membership = await tx.membership.create({
|
||||||
|
data: {
|
||||||
|
userId: targetUserId,
|
||||||
|
organizationId,
|
||||||
|
isOwner: false,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
if (permissionRows.length > 0) {
|
||||||
|
await tx.membershipPermission.createMany({
|
||||||
|
data: permissionRows.map((p) => ({
|
||||||
|
membershipId: membership.id,
|
||||||
|
permissionId: p.id,
|
||||||
|
})),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return { membershipId: membership.id, userId: targetUserId };
|
||||||
|
});
|
||||||
|
|
||||||
|
return {
|
||||||
|
success: true,
|
||||||
|
data: {
|
||||||
|
membershipId: result.membershipId,
|
||||||
|
userId: result.userId,
|
||||||
|
email,
|
||||||
|
temporaryPassword,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async updateMember(
|
||||||
|
actorUserId: string,
|
||||||
|
organizationId: string,
|
||||||
|
membershipId: string,
|
||||||
|
dto: UpdateStaffMemberDto,
|
||||||
|
) {
|
||||||
|
const actor = await this.getActorMembership(actorUserId, organizationId);
|
||||||
|
if (!actor || !this.canEditStaff(actor)) {
|
||||||
|
throw new ForbiddenException('You cannot edit staff');
|
||||||
|
}
|
||||||
|
|
||||||
|
const target = await this.prisma.membership.findFirst({
|
||||||
|
where: { id: membershipId, organizationId },
|
||||||
|
include: {
|
||||||
|
user: true,
|
||||||
|
permissions: { include: { permission: true } },
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!target) {
|
||||||
|
throw new NotFoundException('Member not found');
|
||||||
|
}
|
||||||
|
if (target.isOwner) {
|
||||||
|
throw new ForbiddenException('Owner membership cannot be edited here');
|
||||||
|
}
|
||||||
|
|
||||||
|
if (dto.name !== undefined) {
|
||||||
|
await this.prisma.user.update({
|
||||||
|
where: { id: target.userId },
|
||||||
|
data: { name: dto.name.trim() },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (dto.permissionNames !== undefined) {
|
||||||
|
const normalizedPerms = normalizeTabPermissions(dto.permissionNames);
|
||||||
|
const permissionRows = await this.prisma.permission.findMany({
|
||||||
|
where: { name: { in: normalizedPerms } },
|
||||||
|
select: { id: true, name: true },
|
||||||
|
});
|
||||||
|
if (permissionRows.length !== normalizedPerms.length) {
|
||||||
|
const ok = new Set(permissionRows.map((p) => p.name));
|
||||||
|
const missing = normalizedPerms.filter((n) => !ok.has(n));
|
||||||
|
throw new BadRequestException(`Unknown or invalid permissions: ${missing.join(', ')}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.prisma.$transaction([
|
||||||
|
this.prisma.membershipPermission.deleteMany({ where: { membershipId: target.id } }),
|
||||||
|
...(permissionRows.length
|
||||||
|
? [
|
||||||
|
this.prisma.membershipPermission.createMany({
|
||||||
|
data: permissionRows.map((p) => ({
|
||||||
|
membershipId: target.id,
|
||||||
|
permissionId: p.id,
|
||||||
|
})),
|
||||||
|
}),
|
||||||
|
]
|
||||||
|
: []),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return { success: true, message: 'Member updated' };
|
||||||
|
}
|
||||||
|
|
||||||
|
async removeMember(actorUserId: string, organizationId: string, membershipId: string) {
|
||||||
|
const actor = await this.getActorMembership(actorUserId, organizationId);
|
||||||
|
if (!actor || !this.canEditStaff(actor)) {
|
||||||
|
throw new ForbiddenException('You cannot remove staff');
|
||||||
|
}
|
||||||
|
|
||||||
|
const target = await this.prisma.membership.findFirst({
|
||||||
|
where: { id: membershipId, organizationId },
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!target) {
|
||||||
|
throw new NotFoundException('Member not found');
|
||||||
|
}
|
||||||
|
if (target.isOwner) {
|
||||||
|
throw new ForbiddenException('Cannot remove the organization owner');
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.prisma.membership.delete({ where: { id: membershipId } });
|
||||||
|
|
||||||
|
return { success: true, message: 'Member removed' };
|
||||||
|
}
|
||||||
|
|
||||||
|
private async getActorMembership(userId: string, organizationId: string) {
|
||||||
|
return this.prisma.membership.findFirst({
|
||||||
|
where: { userId, organizationId },
|
||||||
|
include: { permissions: { include: { permission: true } } },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private canViewStaff(m: {
|
||||||
|
isOwner: boolean;
|
||||||
|
permissions: { permission: { name: string } }[];
|
||||||
|
}): boolean {
|
||||||
|
if (m.isOwner) return true;
|
||||||
|
return m.permissions.some(
|
||||||
|
(p) =>
|
||||||
|
p.permission.name === 'TAB_STAFF_READ' || p.permission.name === 'TAB_STAFF_EDIT',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private canEditStaff(m: {
|
||||||
|
isOwner: boolean;
|
||||||
|
permissions: { permission: { name: string } }[];
|
||||||
|
}): boolean {
|
||||||
|
if (m.isOwner) return true;
|
||||||
|
return m.permissions.some((p) => p.permission.name === 'TAB_STAFF_EDIT');
|
||||||
|
}
|
||||||
|
}
|
||||||
56
frontend/src/access/dashboard-tab-access.ts
Normal file
56
frontend/src/access/dashboard-tab-access.ts
Normal file
@@ -0,0 +1,56 @@
|
|||||||
|
/**
|
||||||
|
* Dashboard route ↔ TAB_* READ permission mapping and helpers used by the shell
|
||||||
|
* (Sidebar, layout guard). Cross-cutting access logic lives here — not in `lib`,
|
||||||
|
* which remains for generic utilities (API client, hooks, etc.).
|
||||||
|
*/
|
||||||
|
import type { Organization } from '@/types';
|
||||||
|
|
||||||
|
const ROUTE_TAB_READ: { prefix: string; permission: string }[] = [
|
||||||
|
{ prefix: '/today', permission: 'TAB_TODAY_READ' },
|
||||||
|
{ prefix: '/patients', permission: 'TAB_PATIENTS_READ' },
|
||||||
|
{ prefix: '/appointments', permission: 'TAB_APPOINTMENTS_READ' },
|
||||||
|
{ prefix: '/staff', permission: 'TAB_STAFF_READ' },
|
||||||
|
{ prefix: '/lab', permission: 'TAB_LAB_READ' },
|
||||||
|
{ prefix: '/billing', permission: 'TAB_BILLING_READ' },
|
||||||
|
{ prefix: '/reports', permission: 'TAB_REPORTS_READ' },
|
||||||
|
];
|
||||||
|
|
||||||
|
export function hasPermission(org: Organization | null, permission: string): boolean {
|
||||||
|
if (!org) return false;
|
||||||
|
if (org.isOwner) return true;
|
||||||
|
return Boolean(org.permissions?.includes(permission));
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Sidebar / route guard: READ access to a tab */
|
||||||
|
export function canViewTab(org: Organization | null, readPermission: string): boolean {
|
||||||
|
return hasPermission(org, readPermission);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getRequiredReadPermissionForPath(pathname: string): string | null {
|
||||||
|
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||||
|
if (pathname === prefix || pathname.startsWith(`${prefix}/`)) {
|
||||||
|
return permission;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** First dashboard route the user may open (ordered). Fallback: account settings. */
|
||||||
|
export function firstAccessibleDashboardPath(org: Organization | null): string {
|
||||||
|
if (!org) return '/today';
|
||||||
|
if (org.isOwner) return '/today';
|
||||||
|
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||||
|
if (hasPermission(org, permission)) return prefix;
|
||||||
|
}
|
||||||
|
return '/settings/account';
|
||||||
|
}
|
||||||
|
|
||||||
|
export function canEditStaff(org: Organization | null): boolean {
|
||||||
|
return hasPermission(org, 'TAB_STAFF_EDIT');
|
||||||
|
}
|
||||||
|
|
||||||
|
export function canViewStaff(org: Organization | null): boolean {
|
||||||
|
return (
|
||||||
|
hasPermission(org, 'TAB_STAFF_READ') || hasPermission(org, 'TAB_STAFF_EDIT')
|
||||||
|
);
|
||||||
|
}
|
||||||
1
frontend/src/access/index.ts
Normal file
1
frontend/src/access/index.ts
Normal file
@@ -0,0 +1 @@
|
|||||||
|
export * from './dashboard-tab-access';
|
||||||
@@ -1,15 +1,21 @@
|
|||||||
'use client';
|
'use client';
|
||||||
|
|
||||||
import { memo, useEffect } from 'react';
|
import { memo, useEffect } from 'react';
|
||||||
import { useRouter } from 'next/navigation';
|
import { usePathname, useRouter } from 'next/navigation';
|
||||||
import { useAuth } from '@/lib/hooks/useAuth';
|
import { useAuth } from '@/lib/hooks/useAuth';
|
||||||
import Sidebar from '@/components/ui/Sidebar';
|
import Sidebar from '@/components/ui/Sidebar';
|
||||||
import { ThemeToggle } from '@/components/ui/ThemeToggle';
|
import { ThemeToggle } from '@/components/ui/ThemeToggle';
|
||||||
import { DashboardAccountMenu } from '@/components/ui/DashboardAccountMenu';
|
import { DashboardAccountMenu } from '@/components/ui/DashboardAccountMenu';
|
||||||
|
import {
|
||||||
|
firstAccessibleDashboardPath,
|
||||||
|
getRequiredReadPermissionForPath,
|
||||||
|
hasPermission,
|
||||||
|
} from '@/access';
|
||||||
|
|
||||||
export default function DashboardLayout({ children }: { children: React.ReactNode }) {
|
export default function DashboardLayout({ children }: { children: React.ReactNode }) {
|
||||||
const { user, currentOrganization, isAuthReady } = useAuth();
|
const { user, currentOrganization, isAuthReady } = useAuth();
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
|
const pathname = usePathname();
|
||||||
|
|
||||||
// ✅ AUTH GUARD (runs once per navigation group)
|
// ✅ AUTH GUARD (runs once per navigation group)
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
@@ -24,7 +30,12 @@ export default function DashboardLayout({ children }: { children: React.ReactNod
|
|||||||
router.replace('/select-organization');
|
router.replace('/select-organization');
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
}, [isAuthReady, user, currentOrganization, router]);
|
|
||||||
|
const required = getRequiredReadPermissionForPath(pathname);
|
||||||
|
if (required && !hasPermission(currentOrganization, required)) {
|
||||||
|
router.replace(firstAccessibleDashboardPath(currentOrganization));
|
||||||
|
}
|
||||||
|
}, [isAuthReady, user, currentOrganization, router, pathname]);
|
||||||
|
|
||||||
// ✅ LOADING ONLY FOR INITIAL LOAD
|
// ✅ LOADING ONLY FOR INITIAL LOAD
|
||||||
if (!isAuthReady) {
|
if (!isAuthReady) {
|
||||||
|
|||||||
@@ -10,10 +10,10 @@ import {
|
|||||||
Patient,
|
Patient,
|
||||||
TreatmentHistoryItem,
|
TreatmentHistoryItem,
|
||||||
} from '@/types/patient';
|
} from '@/types/patient';
|
||||||
import { PatientSearchSelect } from '@/components/patients/PatientSearchSelect';
|
import { PatientSearchSelect } from './components/PatientSearchSelect';
|
||||||
import { CreatePatientModal } from '@/components/patients/CreatePatientModal';
|
import { CreatePatientModal } from './components/CreatePatientModal';
|
||||||
import { PatientSummaryCard } from '@/components/patients/PatientSummaryCard';
|
import { PatientSummaryCard } from './components/PatientSummaryCard';
|
||||||
import { TreatmentHistoryPreview } from '@/components/patients/TreatmentHistoryPreview';
|
import { TreatmentHistoryPreview } from './components/TreatmentHistoryPreview';
|
||||||
|
|
||||||
const EMPTY_PATIENT_FORM: CreatePatientInput = {
|
const EMPTY_PATIENT_FORM: CreatePatientInput = {
|
||||||
firstName: '',
|
firstName: '',
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
/** Feature groups for staff invite/edit UI — matches backend seed */
|
||||||
|
export const STAFF_FEATURE_GROUPS = [
|
||||||
|
{ label: 'Today', read: 'TAB_TODAY_READ', edit: 'TAB_TODAY_EDIT' },
|
||||||
|
{ label: 'Patients', read: 'TAB_PATIENTS_READ', edit: 'TAB_PATIENTS_EDIT' },
|
||||||
|
{ label: 'Appointments', read: 'TAB_APPOINTMENTS_READ', edit: 'TAB_APPOINTMENTS_EDIT' },
|
||||||
|
{ label: 'Staff Management', read: 'TAB_STAFF_READ', edit: 'TAB_STAFF_EDIT' },
|
||||||
|
{ label: 'Lab Management', read: 'TAB_LAB_READ', edit: 'TAB_LAB_EDIT' },
|
||||||
|
{ label: 'Billing', read: 'TAB_BILLING_READ', edit: 'TAB_BILLING_EDIT' },
|
||||||
|
{ label: 'Reports', read: 'TAB_REPORTS_READ', edit: 'TAB_REPORTS_EDIT' },
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
/** Map EDIT key -> { read, edit } for checkbox grid */
|
||||||
|
export type FeaturePermState = Record<string, { read: boolean; edit: boolean }>;
|
||||||
|
|
||||||
|
export function emptyFeaturePermissionState(): FeaturePermState {
|
||||||
|
const s: FeaturePermState = {};
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
s[g.edit] = { read: false, edit: false };
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function featureStateFromPermissionNames(names: string[]): FeaturePermState {
|
||||||
|
const set = new Set(names);
|
||||||
|
const s = emptyFeaturePermissionState();
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
const hasEdit = set.has(g.edit);
|
||||||
|
const hasRead = set.has(g.read) || hasEdit;
|
||||||
|
s[g.edit] = { read: hasRead, edit: hasEdit };
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function permissionNamesFromFeatureState(state: FeaturePermState): string[] {
|
||||||
|
const out: string[] = [];
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
const cell = state[g.edit];
|
||||||
|
if (!cell) continue;
|
||||||
|
if (cell.edit) out.push(g.edit);
|
||||||
|
else if (cell.read) out.push(g.read);
|
||||||
|
}
|
||||||
|
return out;
|
||||||
|
}
|
||||||
@@ -1,10 +1,497 @@
|
|||||||
export default function StaffPage() {
|
'use client';
|
||||||
|
|
||||||
|
import { useCallback, useEffect, useMemo, useState } from 'react';
|
||||||
|
import { useRouter } from 'next/navigation';
|
||||||
|
import {
|
||||||
|
firstAccessibleDashboardPath,
|
||||||
|
canEditStaff,
|
||||||
|
canViewStaff,
|
||||||
|
} from '@/access';
|
||||||
|
import {
|
||||||
|
STAFF_FEATURE_GROUPS,
|
||||||
|
permissionNamesFromFeatureState,
|
||||||
|
emptyFeaturePermissionState,
|
||||||
|
featureStateFromPermissionNames,
|
||||||
|
formatAccessSummary,
|
||||||
|
type FeaturePermState,
|
||||||
|
} from './staff-permission-form';
|
||||||
|
import { UserPlus, Pencil, Trash2, Copy, Check, X } from 'lucide-react';
|
||||||
|
import { useAuth } from '@/lib/hooks/useAuth';
|
||||||
|
import { staffApi, type StaffMemberDto } from '@/lib/api/staff';
|
||||||
|
import { Button } from '@/components/ui/Button';
|
||||||
|
import { Input } from '@/components/ui/Input';
|
||||||
|
import { Checkbox } from '@/components/ui/Checkbox';
|
||||||
|
import { ApiError } from '@/types';
|
||||||
|
|
||||||
|
function formatApiMessage(err: unknown): string {
|
||||||
|
if (!err || typeof err !== 'object') return 'Something went wrong';
|
||||||
|
const m = (err as ApiError).message;
|
||||||
|
if (Array.isArray(m)) return m.join(', ');
|
||||||
|
if (typeof m === 'string') return m;
|
||||||
|
return 'Something went wrong';
|
||||||
|
}
|
||||||
|
|
||||||
|
function PermissionGrid({
|
||||||
|
state,
|
||||||
|
onChange,
|
||||||
|
disabled,
|
||||||
|
}: {
|
||||||
|
state: FeaturePermState;
|
||||||
|
onChange: (next: FeaturePermState) => void;
|
||||||
|
disabled?: boolean;
|
||||||
|
}) {
|
||||||
|
const setRead = (editKey: string, read: boolean) => {
|
||||||
|
const cur = state[editKey] ?? { read: false, edit: false };
|
||||||
|
onChange({
|
||||||
|
...state,
|
||||||
|
[editKey]: { read, edit: read ? cur.edit : false },
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
|
const setEdit = (editKey: string, edit: boolean) => {
|
||||||
|
const cur = state[editKey] ?? { read: false, edit: false };
|
||||||
|
onChange({
|
||||||
|
...state,
|
||||||
|
[editKey]: { read: edit || cur.read, edit },
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="space-y-3">
|
<div className="grid gap-3 sm:grid-cols-2">
|
||||||
<h1 className="text-2xl font-semibold text-text-primary">Staff Management</h1>
|
{STAFF_FEATURE_GROUPS.map((g) => {
|
||||||
<p className="text-sm text-text-secondary">
|
const cell = state[g.edit] ?? { read: false, edit: false };
|
||||||
Staff management module is coming soon.
|
return (
|
||||||
</p>
|
<div
|
||||||
|
key={g.edit}
|
||||||
|
className="flex flex-col gap-3 rounded-[var(--radius-md)] border border-border/60 bg-background-card/50 px-3 py-3"
|
||||||
|
>
|
||||||
|
<span className="text-sm font-medium text-text-primary">{g.label}</span>
|
||||||
|
<div className="flex flex-col gap-2.5 pl-0.5">
|
||||||
|
<Checkbox
|
||||||
|
checked={cell.read}
|
||||||
|
disabled={disabled}
|
||||||
|
label="View"
|
||||||
|
onChange={(v) => setRead(g.edit, v)}
|
||||||
|
/>
|
||||||
|
<Checkbox
|
||||||
|
checked={cell.edit}
|
||||||
|
disabled={disabled}
|
||||||
|
label="Edit"
|
||||||
|
onChange={(v) => setEdit(g.edit, v)}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export default function StaffPage() {
|
||||||
|
const router = useRouter();
|
||||||
|
const { currentOrganization, user } = useAuth();
|
||||||
|
const [members, setMembers] = useState<StaffMemberDto[]>([]);
|
||||||
|
const [seats, setSeats] = useState<{
|
||||||
|
used: number;
|
||||||
|
limit: number | null;
|
||||||
|
unlimited: boolean;
|
||||||
|
} | null>(null);
|
||||||
|
const [loading, setLoading] = useState(true);
|
||||||
|
const [error, setError] = useState('');
|
||||||
|
const [success, setSuccess] = useState('');
|
||||||
|
|
||||||
|
const [inviteOpen, setInviteOpen] = useState(false);
|
||||||
|
const [inviteEmail, setInviteEmail] = useState('');
|
||||||
|
const [inviteName, setInviteName] = useState('');
|
||||||
|
const [invitePerms, setInvitePerms] = useState(() => emptyFeaturePermissionState());
|
||||||
|
const [inviteLoading, setInviteLoading] = useState(false);
|
||||||
|
const [lastTempPassword, setLastTempPassword] = useState<string | null>(null);
|
||||||
|
const [copiedPw, setCopiedPw] = useState(false);
|
||||||
|
const [lastInviteInfo, setLastInviteInfo] = useState<{
|
||||||
|
name: string;
|
||||||
|
email: string;
|
||||||
|
isNewAccount: boolean;
|
||||||
|
} | null>(null);
|
||||||
|
|
||||||
|
const [editing, setEditing] = useState<StaffMemberDto | null>(null);
|
||||||
|
const [editName, setEditName] = useState('');
|
||||||
|
const [editPerms, setEditPerms] = useState(() => emptyFeaturePermissionState());
|
||||||
|
const [editLoading, setEditLoading] = useState(false);
|
||||||
|
|
||||||
|
const canEdit = useMemo(() => canEditStaff(currentOrganization), [currentOrganization]);
|
||||||
|
const atSeatLimit = useMemo(() => {
|
||||||
|
if (!seats || seats.unlimited) return false;
|
||||||
|
if (seats.limit == null) return false;
|
||||||
|
return seats.used >= seats.limit;
|
||||||
|
}, [seats]);
|
||||||
|
|
||||||
|
const load = useCallback(async () => {
|
||||||
|
setError('');
|
||||||
|
setLoading(true);
|
||||||
|
try {
|
||||||
|
const res = await staffApi.list();
|
||||||
|
setMembers(res.data.members);
|
||||||
|
setSeats(res.data.seats);
|
||||||
|
} catch (e) {
|
||||||
|
setError(formatApiMessage(e));
|
||||||
|
} finally {
|
||||||
|
setLoading(false);
|
||||||
|
}
|
||||||
|
}, []);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
void load();
|
||||||
|
}, [load]);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (!currentOrganization) return;
|
||||||
|
if (!canViewStaff(currentOrganization)) {
|
||||||
|
router.replace(firstAccessibleDashboardPath(currentOrganization));
|
||||||
|
}
|
||||||
|
}, [currentOrganization, router]);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (!success) return;
|
||||||
|
const t = setTimeout(() => setSuccess(''), 4000);
|
||||||
|
return () => clearTimeout(t);
|
||||||
|
}, [success]);
|
||||||
|
|
||||||
|
async function submitInvite() {
|
||||||
|
setInviteLoading(true);
|
||||||
|
setError('');
|
||||||
|
setLastTempPassword(null);
|
||||||
|
setLastInviteInfo(null);
|
||||||
|
const displayName = inviteName.trim();
|
||||||
|
const displayEmail = inviteEmail.trim();
|
||||||
|
try {
|
||||||
|
const permissionNames = permissionNamesFromFeatureState(invitePerms);
|
||||||
|
const res = await staffApi.invite({
|
||||||
|
email: displayEmail,
|
||||||
|
name: displayName,
|
||||||
|
permissionNames,
|
||||||
|
});
|
||||||
|
const isNew = Boolean(res.data.temporaryPassword);
|
||||||
|
setLastTempPassword(res.data.temporaryPassword);
|
||||||
|
setLastInviteInfo({
|
||||||
|
name: displayName,
|
||||||
|
email: res.data.email,
|
||||||
|
isNewAccount: isNew,
|
||||||
|
});
|
||||||
|
setSuccess('');
|
||||||
|
setInviteOpen(false);
|
||||||
|
setInviteEmail('');
|
||||||
|
setInviteName('');
|
||||||
|
setInvitePerms(emptyFeaturePermissionState());
|
||||||
|
await load();
|
||||||
|
} catch (e) {
|
||||||
|
setError(formatApiMessage(e));
|
||||||
|
} finally {
|
||||||
|
setInviteLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function openEdit(m: StaffMemberDto) {
|
||||||
|
if (m.isOwner) return;
|
||||||
|
setEditing(m);
|
||||||
|
setEditName(m.name);
|
||||||
|
setEditPerms(
|
||||||
|
featureStateFromPermissionNames(m.permissions ?? []),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function submitEdit() {
|
||||||
|
if (!editing) return;
|
||||||
|
setEditLoading(true);
|
||||||
|
setError('');
|
||||||
|
try {
|
||||||
|
await staffApi.updateMember(editing.id, {
|
||||||
|
name: editName.trim(),
|
||||||
|
permissionNames: permissionNamesFromFeatureState(editPerms),
|
||||||
|
});
|
||||||
|
setSuccess('Member updated');
|
||||||
|
setEditing(null);
|
||||||
|
await load();
|
||||||
|
} catch (e) {
|
||||||
|
setError(formatApiMessage(e));
|
||||||
|
} finally {
|
||||||
|
setEditLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function removeMember(m: StaffMemberDto) {
|
||||||
|
if (m.isOwner) return;
|
||||||
|
if (m.userId === user?.id) {
|
||||||
|
if (!confirm('Remove yourself from this organization? You will lose access.')) return;
|
||||||
|
} else {
|
||||||
|
if (!confirm(`Remove ${m.name} from this organization?`)) return;
|
||||||
|
}
|
||||||
|
setError('');
|
||||||
|
try {
|
||||||
|
await staffApi.removeMember(m.id);
|
||||||
|
setSuccess('Member removed');
|
||||||
|
await load();
|
||||||
|
} catch (e) {
|
||||||
|
setError(formatApiMessage(e));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function copyTempPassword() {
|
||||||
|
if (!lastTempPassword) return;
|
||||||
|
try {
|
||||||
|
await navigator.clipboard.writeText(lastTempPassword);
|
||||||
|
setCopiedPw(true);
|
||||||
|
setTimeout(() => setCopiedPw(false), 2000);
|
||||||
|
} catch {
|
||||||
|
setError('Could not copy to clipboard');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!currentOrganization || !canViewStaff(currentOrganization)) {
|
||||||
|
return (
|
||||||
|
<p className="text-sm text-text-secondary">Redirecting…</p>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className="space-y-6 max-w-5xl">
|
||||||
|
<div className="flex flex-col gap-3 sm:flex-row sm:items-start sm:justify-between">
|
||||||
|
<div>
|
||||||
|
<h1 className="text-2xl font-semibold text-text-primary">Staff Management</h1>
|
||||||
|
<p className="text-sm text-text-secondary mt-1">
|
||||||
|
Invite teammates, set tab access, and stay within your plan seat limit.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
{canEdit && (
|
||||||
|
<Button
|
||||||
|
size="sm"
|
||||||
|
onClick={() => {
|
||||||
|
setInviteOpen(true);
|
||||||
|
setLastTempPassword(null);
|
||||||
|
setLastInviteInfo(null);
|
||||||
|
}}
|
||||||
|
disabled={atSeatLimit}
|
||||||
|
className="shrink-0"
|
||||||
|
>
|
||||||
|
<UserPlus className="w-4 h-4 mr-2" />
|
||||||
|
Invite member
|
||||||
|
</Button>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{seats && (
|
||||||
|
<p className="text-sm text-text-secondary">
|
||||||
|
Seats:{' '}
|
||||||
|
<span className="text-text-primary font-medium">
|
||||||
|
{seats.used}
|
||||||
|
{seats.unlimited ? ' (unlimited plan)' : ` / ${seats.limit}`}
|
||||||
|
</span>
|
||||||
|
{!seats.unlimited && atSeatLimit && (
|
||||||
|
<span className="text-amber-600 dark:text-amber-400 ml-2">
|
||||||
|
Limit reached — remove a member or upgrade your plan.
|
||||||
|
</span>
|
||||||
|
)}
|
||||||
|
</p>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{error && (
|
||||||
|
<div className="rounded-[var(--radius-md)] border border-red-500/40 bg-red-500/10 px-4 py-3 text-sm text-red-700 dark:text-red-300">
|
||||||
|
{error}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{success && (
|
||||||
|
<div className="rounded-[var(--radius-md)] border border-primary/30 bg-primary-soft/40 px-4 py-3 text-sm text-text-primary">
|
||||||
|
{success}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{lastInviteInfo && (
|
||||||
|
<div className="relative rounded-[var(--radius-md)] border border-border-strong bg-background-secondary/90 px-4 py-3 pr-12 shadow-[inset_0_1px_0_rgba(255,255,255,0.04)] space-y-3">
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
className="absolute right-2 top-2 p-1.5 rounded-[var(--radius-sm)] text-text-muted hover:text-text-primary hover:bg-background-card/80"
|
||||||
|
aria-label="Dismiss"
|
||||||
|
onClick={() => {
|
||||||
|
setLastInviteInfo(null);
|
||||||
|
setLastTempPassword(null);
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
<X className="w-4 h-4" />
|
||||||
|
</button>
|
||||||
|
<p className="text-sm text-text-primary pr-6">
|
||||||
|
{lastInviteInfo.isNewAccount ? (
|
||||||
|
<>
|
||||||
|
<span className="font-medium">{lastInviteInfo.name}</span> ({lastInviteInfo.email}) — new
|
||||||
|
account created and added to this organization.
|
||||||
|
{lastTempPassword
|
||||||
|
? ' Share the temporary password below so they can sign in.'
|
||||||
|
: ''}
|
||||||
|
</>
|
||||||
|
) : (
|
||||||
|
<>
|
||||||
|
<span className="font-medium">{lastInviteInfo.name}</span> ({lastInviteInfo.email}) — this
|
||||||
|
person already had an account. They can select <span className="font-medium">{currentOrganization.name}</span>{' '}
|
||||||
|
from the organization switcher after signing in.
|
||||||
|
</>
|
||||||
|
)}
|
||||||
|
</p>
|
||||||
|
{lastTempPassword && (
|
||||||
|
<div className="space-y-2 pt-1 border-t border-border/60">
|
||||||
|
<p className="text-xs font-medium text-text-secondary uppercase tracking-wide">
|
||||||
|
Temporary password (copy now — not stored)
|
||||||
|
</p>
|
||||||
|
<div className="flex flex-wrap items-center gap-2">
|
||||||
|
<code className="text-sm px-2 py-1.5 rounded-[var(--radius-sm)] bg-background-card border border-border font-mono">
|
||||||
|
{lastTempPassword}
|
||||||
|
</code>
|
||||||
|
<Button type="button" variant="outline" size="sm" onClick={() => void copyTempPassword()}>
|
||||||
|
{copiedPw ? <Check className="w-4 h-4" /> : <Copy className="w-4 h-4" />}
|
||||||
|
<span className="ml-1">{copiedPw ? 'Copied' : 'Copy'}</span>
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
<p className="text-xs text-text-muted">
|
||||||
|
They should sign in with this password once, then change it under account settings.
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{loading ? (
|
||||||
|
<p className="text-sm text-text-secondary">Loading team…</p>
|
||||||
|
) : (
|
||||||
|
<div className="overflow-x-auto rounded-[var(--radius-md)] border border-border/70">
|
||||||
|
<table className="w-full text-sm">
|
||||||
|
<thead>
|
||||||
|
<tr className="border-b border-border/70 text-left text-text-secondary">
|
||||||
|
<th className="p-3 font-medium">Name</th>
|
||||||
|
<th className="p-3 font-medium">Email</th>
|
||||||
|
<th className="p-3 font-medium">Role</th>
|
||||||
|
<th className="p-3 font-medium">Access</th>
|
||||||
|
{canEdit && <th className="p-3 font-medium w-28">Actions</th>}
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
<tbody>
|
||||||
|
{members.map((m) => (
|
||||||
|
<tr key={m.id} className="border-b border-border/40 last:border-0">
|
||||||
|
<td className="p-3 text-text-primary">{m.name}</td>
|
||||||
|
<td className="p-3 text-text-secondary">{m.email}</td>
|
||||||
|
<td className="p-3">
|
||||||
|
{m.isOwner ? (
|
||||||
|
<span className="text-primary font-medium">Owner</span>
|
||||||
|
) : (
|
||||||
|
<span className="text-text-secondary">Staff</span>
|
||||||
|
)}
|
||||||
|
</td>
|
||||||
|
<td className="p-3 text-text-secondary max-w-md">
|
||||||
|
{m.isOwner ? (
|
||||||
|
<span className="text-text-muted">All features</span>
|
||||||
|
) : (
|
||||||
|
<span className="line-clamp-3 text-sm leading-relaxed">
|
||||||
|
{formatAccessSummary(m.permissions)}
|
||||||
|
</span>
|
||||||
|
)}
|
||||||
|
</td>
|
||||||
|
{canEdit && (
|
||||||
|
<td className="p-3">
|
||||||
|
{!m.isOwner && (
|
||||||
|
<div className="flex items-center gap-1">
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
className="p-2 rounded-md text-text-secondary hover:bg-background-card/80 hover:text-text-primary"
|
||||||
|
aria-label="Edit member"
|
||||||
|
onClick={() => openEdit(m)}
|
||||||
|
>
|
||||||
|
<Pencil className="w-4 h-4" />
|
||||||
|
</button>
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
className="p-2 rounded-md text-text-secondary hover:bg-red-500/15 hover:text-red-600"
|
||||||
|
aria-label="Remove member"
|
||||||
|
onClick={() => void removeMember(m)}
|
||||||
|
>
|
||||||
|
<Trash2 className="w-4 h-4" />
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
</td>
|
||||||
|
)}
|
||||||
|
</tr>
|
||||||
|
))}
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{inviteOpen && (
|
||||||
|
<div className="fixed inset-0 z-50 flex items-center justify-center p-4 bg-black/50">
|
||||||
|
<div
|
||||||
|
className="w-full max-w-lg max-h-[90vh] overflow-y-auto rounded-[var(--radius-md)] border border-border bg-background-secondary p-6 shadow-xl space-y-4"
|
||||||
|
role="dialog"
|
||||||
|
aria-modal="true"
|
||||||
|
aria-labelledby="invite-staff-title"
|
||||||
|
>
|
||||||
|
<h2 id="invite-staff-title" className="text-lg font-semibold text-text-primary">
|
||||||
|
Invite team member
|
||||||
|
</h2>
|
||||||
|
<Input
|
||||||
|
label="Email"
|
||||||
|
type="email"
|
||||||
|
value={inviteEmail}
|
||||||
|
onChange={(e) => setInviteEmail(e.target.value)}
|
||||||
|
autoComplete="off"
|
||||||
|
/>
|
||||||
|
<Input
|
||||||
|
label="Display name"
|
||||||
|
value={inviteName}
|
||||||
|
onChange={(e) => setInviteName(e.target.value)}
|
||||||
|
/>
|
||||||
|
<div>
|
||||||
|
<p className="text-sm font-medium text-text-secondary mb-2">Tab access</p>
|
||||||
|
<PermissionGrid state={invitePerms} onChange={setInvitePerms} />
|
||||||
|
</div>
|
||||||
|
<div className="flex justify-end gap-2 pt-2">
|
||||||
|
<Button variant="outline" type="button" onClick={() => setInviteOpen(false)}>
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
<Button
|
||||||
|
type="button"
|
||||||
|
isLoading={inviteLoading}
|
||||||
|
disabled={!inviteEmail.trim() || !inviteName.trim()}
|
||||||
|
onClick={() => void submitInvite()}
|
||||||
|
>
|
||||||
|
Send invite
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{editing && (
|
||||||
|
<div className="fixed inset-0 z-50 flex items-center justify-center p-4 bg-black/50">
|
||||||
|
<div
|
||||||
|
className="w-full max-w-lg max-h-[90vh] overflow-y-auto rounded-[var(--radius-md)] border border-border bg-background-secondary p-6 shadow-xl space-y-4"
|
||||||
|
role="dialog"
|
||||||
|
aria-modal="true"
|
||||||
|
>
|
||||||
|
<h2 className="text-lg font-semibold text-text-primary">Edit member</h2>
|
||||||
|
<p className="text-xs text-text-muted">{editing.email}</p>
|
||||||
|
<Input label="Display name" value={editName} onChange={(e) => setEditName(e.target.value)} />
|
||||||
|
<div>
|
||||||
|
<p className="text-sm font-medium text-text-secondary mb-2">Tab access</p>
|
||||||
|
<PermissionGrid state={editPerms} onChange={setEditPerms} />
|
||||||
|
</div>
|
||||||
|
<div className="flex justify-end gap-2 pt-2">
|
||||||
|
<Button variant="outline" type="button" onClick={() => setEditing(null)}>
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
<Button type="button" isLoading={editLoading} onClick={() => void submitEdit()}>
|
||||||
|
Save
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
60
frontend/src/app/(dashboard)/staff/staff-permission-form.ts
Normal file
60
frontend/src/app/(dashboard)/staff/staff-permission-form.ts
Normal file
@@ -0,0 +1,60 @@
|
|||||||
|
/**
|
||||||
|
* Staff route only: tab matrix + checkbox state ↔ TAB_* permission names.
|
||||||
|
* Add presentational pieces under ./components/ as the UI grows.
|
||||||
|
*/
|
||||||
|
|
||||||
|
export const STAFF_FEATURE_GROUPS = [
|
||||||
|
{ label: 'Today', read: 'TAB_TODAY_READ', edit: 'TAB_TODAY_EDIT' },
|
||||||
|
{ label: 'Patients', read: 'TAB_PATIENTS_READ', edit: 'TAB_PATIENTS_EDIT' },
|
||||||
|
{ label: 'Appointments', read: 'TAB_APPOINTMENTS_READ', edit: 'TAB_APPOINTMENTS_EDIT' },
|
||||||
|
{ label: 'Staff Management', read: 'TAB_STAFF_READ', edit: 'TAB_STAFF_EDIT' },
|
||||||
|
{ label: 'Lab Management', read: 'TAB_LAB_READ', edit: 'TAB_LAB_EDIT' },
|
||||||
|
{ label: 'Billing', read: 'TAB_BILLING_READ', edit: 'TAB_BILLING_EDIT' },
|
||||||
|
{ label: 'Reports', read: 'TAB_REPORTS_READ', edit: 'TAB_REPORTS_EDIT' },
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
export type FeaturePermState = Record<string, { read: boolean; edit: boolean }>;
|
||||||
|
|
||||||
|
export function emptyFeaturePermissionState(): FeaturePermState {
|
||||||
|
const s: FeaturePermState = {};
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
s[g.edit] = { read: false, edit: false };
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function featureStateFromPermissionNames(names: string[]): FeaturePermState {
|
||||||
|
const set = new Set(names);
|
||||||
|
const s = emptyFeaturePermissionState();
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
const hasEdit = set.has(g.edit);
|
||||||
|
const hasRead = set.has(g.read) || hasEdit;
|
||||||
|
s[g.edit] = { read: hasRead, edit: hasEdit };
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function permissionNamesFromFeatureState(state: FeaturePermState): string[] {
|
||||||
|
const out: string[] = [];
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
const cell = state[g.edit];
|
||||||
|
if (!cell) continue;
|
||||||
|
if (cell.edit) out.push(g.edit);
|
||||||
|
else if (cell.read) out.push(g.read);
|
||||||
|
}
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Human-readable access for the team table — feature name, or "Feature (Read only)" */
|
||||||
|
export function formatAccessSummary(permissionNames: string[] | null | undefined): string {
|
||||||
|
if (!permissionNames?.length) return 'No tab access';
|
||||||
|
const set = new Set(permissionNames);
|
||||||
|
const parts: string[] = [];
|
||||||
|
for (const g of STAFF_FEATURE_GROUPS) {
|
||||||
|
const hasEdit = set.has(g.edit);
|
||||||
|
const hasRead = set.has(g.read) || hasEdit;
|
||||||
|
if (!hasRead) continue;
|
||||||
|
parts.push(hasEdit ? g.label : `${g.label} (Read only)`);
|
||||||
|
}
|
||||||
|
return parts.length ? parts.join(' · ') : 'No tab access';
|
||||||
|
}
|
||||||
70
frontend/src/components/ui/Checkbox.tsx
Normal file
70
frontend/src/components/ui/Checkbox.tsx
Normal file
@@ -0,0 +1,70 @@
|
|||||||
|
'use client';
|
||||||
|
|
||||||
|
import { useId } from 'react';
|
||||||
|
import { Check } from 'lucide-react';
|
||||||
|
|
||||||
|
type CheckboxProps = {
|
||||||
|
checked: boolean;
|
||||||
|
onChange: (checked: boolean) => void;
|
||||||
|
disabled?: boolean;
|
||||||
|
label: string;
|
||||||
|
id?: string;
|
||||||
|
className?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* App design-system checkbox: primary fill when checked, rounded, focus-visible ring.
|
||||||
|
*/
|
||||||
|
export function Checkbox({
|
||||||
|
checked,
|
||||||
|
onChange,
|
||||||
|
disabled = false,
|
||||||
|
label,
|
||||||
|
id,
|
||||||
|
className = '',
|
||||||
|
}: CheckboxProps) {
|
||||||
|
const genId = useId();
|
||||||
|
const inputId = id ?? genId;
|
||||||
|
|
||||||
|
return (
|
||||||
|
<label
|
||||||
|
htmlFor={inputId}
|
||||||
|
className={`
|
||||||
|
inline-flex items-center gap-2.5 cursor-pointer select-none rounded-[var(--radius-sm)] -m-0.5 p-0.5
|
||||||
|
has-[:focus-visible]:ring-2 has-[:focus-visible]:ring-primary/45 has-[:focus-visible]:ring-offset-2
|
||||||
|
has-[:focus-visible]:ring-offset-background-secondary
|
||||||
|
${disabled ? 'opacity-50 cursor-not-allowed' : ''}
|
||||||
|
${className}
|
||||||
|
`}
|
||||||
|
>
|
||||||
|
<input
|
||||||
|
id={inputId}
|
||||||
|
type="checkbox"
|
||||||
|
className="sr-only"
|
||||||
|
checked={checked}
|
||||||
|
disabled={disabled}
|
||||||
|
onChange={(e) => onChange(e.target.checked)}
|
||||||
|
/>
|
||||||
|
<span
|
||||||
|
className={`
|
||||||
|
flex h-5 w-5 shrink-0 items-center justify-center rounded-[var(--radius-sm)] border-2 transition-all duration-200
|
||||||
|
shadow-[inset_0_1px_0_rgba(255,255,255,0.05)]
|
||||||
|
${
|
||||||
|
checked
|
||||||
|
? 'border-primary bg-primary shadow-[0_0_0_1px_rgba(9,169,188,0.25)]'
|
||||||
|
: 'border-border-strong bg-background-card/90 hover:border-border'
|
||||||
|
}
|
||||||
|
`}
|
||||||
|
aria-hidden
|
||||||
|
>
|
||||||
|
<Check
|
||||||
|
strokeWidth={3}
|
||||||
|
className={`h-3.5 w-3.5 text-primary-contrast transition-all duration-200 ${
|
||||||
|
checked ? 'scale-100 opacity-100' : 'scale-75 opacity-0'
|
||||||
|
}`}
|
||||||
|
/>
|
||||||
|
</span>
|
||||||
|
<span className="text-sm text-text-secondary">{label}</span>
|
||||||
|
</label>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
'use client';
|
'use client';
|
||||||
|
|
||||||
import Link from 'next/link';
|
import Link from 'next/link';
|
||||||
import { memo } from 'react';
|
import { memo, useMemo } from 'react';
|
||||||
import { usePathname } from 'next/navigation';
|
import { usePathname } from 'next/navigation';
|
||||||
import {
|
import {
|
||||||
LayoutDashboard,
|
LayoutDashboard,
|
||||||
@@ -12,19 +12,27 @@ import {
|
|||||||
FileText,
|
FileText,
|
||||||
CreditCard,
|
CreditCard,
|
||||||
} from 'lucide-react';
|
} from 'lucide-react';
|
||||||
|
import { useAuth } from '@/lib/hooks/useAuth';
|
||||||
|
import { canViewTab } from '@/access';
|
||||||
|
|
||||||
const menu = [
|
const menu = [
|
||||||
{ name: 'Today', path: '/today', icon: LayoutDashboard },
|
{ name: 'Today', path: '/today', icon: LayoutDashboard, read: 'TAB_TODAY_READ' as const },
|
||||||
{ name: 'Patients', path: '/patients', icon: Users },
|
{ name: 'Patients', path: '/patients', icon: Users, read: 'TAB_PATIENTS_READ' as const },
|
||||||
{ name: 'Appointments', path: '/appointments', icon: Calendar },
|
{ name: 'Appointments', path: '/appointments', icon: Calendar, read: 'TAB_APPOINTMENTS_READ' as const },
|
||||||
{ name: 'Staff Management', path: '/staff', icon: UserCog },
|
{ name: 'Staff Management', path: '/staff', icon: UserCog, read: 'TAB_STAFF_READ' as const },
|
||||||
{ name: 'Lab Management', path: '/lab', icon: FlaskConical },
|
{ name: 'Lab Management', path: '/lab', icon: FlaskConical, read: 'TAB_LAB_READ' as const },
|
||||||
{ name: 'Billing', path: '/billing', icon: CreditCard },
|
{ name: 'Billing', path: '/billing', icon: CreditCard, read: 'TAB_BILLING_READ' as const },
|
||||||
{ name: 'Reports', path: '/reports', icon: FileText },
|
{ name: 'Reports', path: '/reports', icon: FileText, read: 'TAB_REPORTS_READ' as const },
|
||||||
];
|
];
|
||||||
|
|
||||||
function Sidebar() {
|
function Sidebar() {
|
||||||
const pathname = usePathname();
|
const pathname = usePathname();
|
||||||
|
const { currentOrganization } = useAuth();
|
||||||
|
|
||||||
|
const visibleMenu = useMemo(
|
||||||
|
() => menu.filter((item) => canViewTab(currentOrganization, item.read)),
|
||||||
|
[currentOrganization],
|
||||||
|
);
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<aside className="w-64 bg-background-secondary/90 border-r border-border text-text-primary flex flex-col">
|
<aside className="w-64 bg-background-secondary/90 border-r border-border text-text-primary flex flex-col">
|
||||||
@@ -34,7 +42,7 @@ function Sidebar() {
|
|||||||
<div className="mx-4 border-b border-border/70" />
|
<div className="mx-4 border-b border-border/70" />
|
||||||
|
|
||||||
<nav className="flex flex-col gap-2 p-4">
|
<nav className="flex flex-col gap-2 p-4">
|
||||||
{menu.map((item) => {
|
{visibleMenu.map((item) => {
|
||||||
const Icon = item.icon;
|
const Icon = item.icon;
|
||||||
const isActive = pathname === item.path;
|
const isActive = pathname === item.path;
|
||||||
|
|
||||||
|
|||||||
63
frontend/src/lib/api/staff.ts
Normal file
63
frontend/src/lib/api/staff.ts
Normal file
@@ -0,0 +1,63 @@
|
|||||||
|
import { apiClient } from './client';
|
||||||
|
|
||||||
|
export interface StaffMemberDto {
|
||||||
|
id: string;
|
||||||
|
userId: string;
|
||||||
|
email: string;
|
||||||
|
name: string;
|
||||||
|
isOwner: boolean;
|
||||||
|
permissions: string[] | null;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface StaffListResponse {
|
||||||
|
success: boolean;
|
||||||
|
data: {
|
||||||
|
members: StaffMemberDto[];
|
||||||
|
seats: {
|
||||||
|
used: number;
|
||||||
|
limit: number | null;
|
||||||
|
unlimited: boolean;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface InviteStaffResponse {
|
||||||
|
success: boolean;
|
||||||
|
data: {
|
||||||
|
membershipId: string;
|
||||||
|
userId: string;
|
||||||
|
email: string;
|
||||||
|
temporaryPassword: string | null;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
export const staffApi = {
|
||||||
|
list: async (): Promise<StaffListResponse> => {
|
||||||
|
const response = await apiClient.get('/staff');
|
||||||
|
return response.data;
|
||||||
|
},
|
||||||
|
|
||||||
|
invite: async (body: {
|
||||||
|
email: string;
|
||||||
|
name: string;
|
||||||
|
permissionNames: string[];
|
||||||
|
}): Promise<InviteStaffResponse> => {
|
||||||
|
const response = await apiClient.post('/staff/invite', body);
|
||||||
|
return response.data;
|
||||||
|
},
|
||||||
|
|
||||||
|
updateMember: async (
|
||||||
|
membershipId: string,
|
||||||
|
body: { name?: string; permissionNames?: string[] },
|
||||||
|
): Promise<{ success: boolean; message: string }> => {
|
||||||
|
const response = await apiClient.patch(`/staff/members/${membershipId}`, body);
|
||||||
|
return response.data;
|
||||||
|
},
|
||||||
|
|
||||||
|
removeMember: async (
|
||||||
|
membershipId: string,
|
||||||
|
): Promise<{ success: boolean; message: string }> => {
|
||||||
|
const response = await apiClient.delete(`/staff/members/${membershipId}`);
|
||||||
|
return response.data;
|
||||||
|
},
|
||||||
|
};
|
||||||
@@ -223,6 +223,7 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
|||||||
name: organization.name,
|
name: organization.name,
|
||||||
type: organization.type as Organization['type'],
|
type: organization.type as Organization['type'],
|
||||||
isOwner: Boolean((organization as { isOwner?: boolean }).isOwner),
|
isOwner: Boolean((organization as { isOwner?: boolean }).isOwner),
|
||||||
|
permissions: (organization as { permissions?: string[] }).permissions,
|
||||||
plan: (organization as { plan?: Organization['plan'] }).plan,
|
plan: (organization as { plan?: Organization['plan'] }).plan,
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
51
frontend/src/shared/permissions.ts
Normal file
51
frontend/src/shared/permissions.ts
Normal file
@@ -0,0 +1,51 @@
|
|||||||
|
import type { Organization } from '@/types';
|
||||||
|
|
||||||
|
const ROUTE_TAB_READ: { prefix: string; permission: string }[] = [
|
||||||
|
{ prefix: '/today', permission: 'TAB_TODAY_READ' },
|
||||||
|
{ prefix: '/patients', permission: 'TAB_PATIENTS_READ' },
|
||||||
|
{ prefix: '/appointments', permission: 'TAB_APPOINTMENTS_READ' },
|
||||||
|
{ prefix: '/staff', permission: 'TAB_STAFF_READ' },
|
||||||
|
{ prefix: '/lab', permission: 'TAB_LAB_READ' },
|
||||||
|
{ prefix: '/billing', permission: 'TAB_BILLING_READ' },
|
||||||
|
{ prefix: '/reports', permission: 'TAB_REPORTS_READ' },
|
||||||
|
];
|
||||||
|
|
||||||
|
export function hasPermission(org: Organization | null, permission: string): boolean {
|
||||||
|
if (!org) return false;
|
||||||
|
if (org.isOwner) return true;
|
||||||
|
return Boolean(org.permissions?.includes(permission));
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Sidebar / route guard: READ access to a tab */
|
||||||
|
export function canViewTab(org: Organization | null, readPermission: string): boolean {
|
||||||
|
return hasPermission(org, readPermission);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getRequiredReadPermissionForPath(pathname: string): string | null {
|
||||||
|
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||||
|
if (pathname === prefix || pathname.startsWith(`${prefix}/`)) {
|
||||||
|
return permission;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** First dashboard route the user may open (ordered). Fallback: account settings. */
|
||||||
|
export function firstAccessibleDashboardPath(org: Organization | null): string {
|
||||||
|
if (!org) return '/today';
|
||||||
|
if (org.isOwner) return '/today';
|
||||||
|
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||||
|
if (hasPermission(org, permission)) return prefix;
|
||||||
|
}
|
||||||
|
return '/settings/account';
|
||||||
|
}
|
||||||
|
|
||||||
|
export function canEditStaff(org: Organization | null): boolean {
|
||||||
|
return hasPermission(org, 'TAB_STAFF_EDIT');
|
||||||
|
}
|
||||||
|
|
||||||
|
export function canViewStaff(org: Organization | null): boolean {
|
||||||
|
return (
|
||||||
|
hasPermission(org, 'TAB_STAFF_READ') || hasPermission(org, 'TAB_STAFF_EDIT')
|
||||||
|
);
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user