Compare commits
7 Commits
bugfix/log
...
feature/st
| Author | SHA1 | Date | |
|---|---|---|---|
| 1387e4cb5e | |||
| 1b8856f64e | |||
| c39bd872bd | |||
| d19da80d8e | |||
| 7a847d5326 | |||
| ca9e684ab4 | |||
| c154b6dabf |
@@ -0,0 +1,2 @@
|
||||
ALTER TABLE "users"
|
||||
ADD COLUMN "trialUsedAt" TIMESTAMP(3);
|
||||
@@ -0,0 +1,29 @@
|
||||
-- AlterTable
|
||||
ALTER TABLE "memberships" ADD COLUMN "isActive" BOOLEAN NOT NULL DEFAULT true;
|
||||
|
||||
-- CreateTable
|
||||
CREATE TABLE "staff_invitations" (
|
||||
"id" TEXT NOT NULL,
|
||||
"membershipId" TEXT NOT NULL,
|
||||
"invitedById" TEXT NOT NULL,
|
||||
"tokenHash" TEXT NOT NULL,
|
||||
"expiresAt" TIMESTAMP(3) NOT NULL,
|
||||
"acceptedAt" TIMESTAMP(3),
|
||||
"revokedAt" TIMESTAMP(3),
|
||||
"createdAt" TIMESTAMP(3) NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
"updatedAt" TIMESTAMP(3) NOT NULL,
|
||||
|
||||
CONSTRAINT "staff_invitations_pkey" PRIMARY KEY ("id")
|
||||
);
|
||||
|
||||
-- CreateIndex
|
||||
CREATE UNIQUE INDEX "staff_invitations_tokenHash_key" ON "staff_invitations"("tokenHash");
|
||||
|
||||
-- CreateIndex
|
||||
CREATE INDEX "staff_invitations_membershipId_createdAt_idx" ON "staff_invitations"("membershipId", "createdAt");
|
||||
|
||||
-- AddForeignKey
|
||||
ALTER TABLE "staff_invitations" ADD CONSTRAINT "staff_invitations_membershipId_fkey" FOREIGN KEY ("membershipId") REFERENCES "memberships"("id") ON DELETE CASCADE ON UPDATE CASCADE;
|
||||
|
||||
-- AddForeignKey
|
||||
ALTER TABLE "staff_invitations" ADD CONSTRAINT "staff_invitations_invitedById_fkey" FOREIGN KEY ("invitedById") REFERENCES "users"("id") ON DELETE CASCADE ON UPDATE CASCADE;
|
||||
@@ -15,10 +15,12 @@ model User {
|
||||
googleId String? @unique
|
||||
facebookId String? @unique
|
||||
name String
|
||||
trialUsedAt DateTime?
|
||||
|
||||
memberships Membership[]
|
||||
ownedOrganizations Organization[] @relation("OrganizationOwner")
|
||||
sessions Session[] // 👈 ADD THIS - opposite relation for Session
|
||||
sentStaffInvites StaffInvitation[]
|
||||
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
@@ -121,11 +123,13 @@ model Membership {
|
||||
organizationId String
|
||||
|
||||
isOwner Boolean @default(false)
|
||||
isActive Boolean @default(true)
|
||||
|
||||
user User @relation(fields: [userId], references: [id])
|
||||
organization Organization @relation(fields: [organizationId], references: [id])
|
||||
|
||||
permissions MembershipPermission[]
|
||||
invitations StaffInvitation[]
|
||||
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
@@ -134,6 +138,26 @@ model Membership {
|
||||
@@map("memberships")
|
||||
}
|
||||
|
||||
model StaffInvitation {
|
||||
id String @id @default(uuid())
|
||||
|
||||
membershipId String
|
||||
invitedById String
|
||||
tokenHash String @unique
|
||||
expiresAt DateTime
|
||||
acceptedAt DateTime?
|
||||
revokedAt DateTime?
|
||||
|
||||
membership Membership @relation(fields: [membershipId], references: [id], onDelete: Cascade)
|
||||
invitedBy User @relation(fields: [invitedById], references: [id], onDelete: Cascade)
|
||||
|
||||
createdAt DateTime @default(now())
|
||||
updatedAt DateTime @updatedAt
|
||||
|
||||
@@index([membershipId, createdAt])
|
||||
@@map("staff_invitations")
|
||||
}
|
||||
|
||||
model Permission {
|
||||
id String @id @default(uuid())
|
||||
name String @unique
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
// backend/prisma/seed.ts
|
||||
import { PrismaClient } from '@prisma/client';
|
||||
import * as bcrypt from 'bcrypt';
|
||||
import { config } from 'dotenv';
|
||||
import path from 'path';
|
||||
|
||||
@@ -29,14 +28,14 @@ async function main() {
|
||||
console.log('✅ Database connected successfully');
|
||||
|
||||
// Create organization types
|
||||
const clinicType = await prisma.organizationType.upsert({
|
||||
await prisma.organizationType.upsert({
|
||||
where: { name: 'CLINIC' },
|
||||
update: {},
|
||||
create: { name: 'CLINIC' },
|
||||
});
|
||||
console.log('✅ Created clinic type');
|
||||
|
||||
const labType = await prisma.organizationType.upsert({
|
||||
await prisma.organizationType.upsert({
|
||||
where: { name: 'LAB' },
|
||||
update: {},
|
||||
create: { name: 'LAB' },
|
||||
@@ -46,10 +45,10 @@ async function main() {
|
||||
// Create plans
|
||||
const plans = [
|
||||
{ name: 'trial', maxUsers: 5, price: 0, features: {} },
|
||||
{ name: 'Small', maxUsers: 5, price: 79, features: {} },
|
||||
{ name: 'Medium', maxUsers: 10, price: 129, features: {} },
|
||||
{ name: 'Large', maxUsers: 15, price: 179, features: {} },
|
||||
{ name: 'Enterprise', maxUsers: 999999, price: 299, features: {} },
|
||||
{ name: 'Small', maxUsers: 5, price: 150, features: {} },
|
||||
{ name: 'Medium', maxUsers: 10, price: 250, features: {} },
|
||||
{ name: 'Large', maxUsers: 15, price: 400, features: {} },
|
||||
{ name: 'Enterprise', maxUsers: 999999, price: 1000, features: {} },
|
||||
];
|
||||
|
||||
for (const plan of plans) {
|
||||
@@ -61,32 +60,39 @@ async function main() {
|
||||
}
|
||||
console.log('✅ Created plans');
|
||||
|
||||
// Create features and permissions
|
||||
// Minimal permission model (confirmed):
|
||||
// - Sidebar tabs use READ/EDIT
|
||||
// - EDIT implies READ in app logic
|
||||
// - Owners effectively get all permissions
|
||||
const features = [
|
||||
{
|
||||
name: 'Patient Management',
|
||||
permissions: ['VIEW_PATIENTS', 'CREATE_PATIENTS', 'EDIT_PATIENTS', 'DELETE_PATIENTS']
|
||||
name: 'Today',
|
||||
permissions: ['TAB_TODAY_READ', 'TAB_TODAY_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Order Management',
|
||||
permissions: ['VIEW_ORDERS', 'CREATE_ORDERS', 'EDIT_ORDERS', 'DELETE_ORDERS', 'TRACK_ORDERS']
|
||||
name: 'Patients',
|
||||
permissions: ['TAB_PATIENTS_READ', 'TAB_PATIENTS_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Case Management',
|
||||
permissions: ['VIEW_CASES', 'CREATE_CASES', 'EDIT_CASES', 'DELETE_CASES']
|
||||
name: 'Appointments',
|
||||
permissions: ['TAB_APPOINTMENTS_READ', 'TAB_APPOINTMENTS_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Reports',
|
||||
permissions: ['VIEW_REPORTS', 'EXPORT_REPORTS']
|
||||
name: 'Staff Management',
|
||||
permissions: ['TAB_STAFF_READ', 'TAB_STAFF_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Team Management',
|
||||
permissions: ['INVITE_USERS', 'REMOVE_USERS', 'MANAGE_PERMISSIONS']
|
||||
name: 'Lab Management',
|
||||
permissions: ['TAB_LAB_READ', 'TAB_LAB_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Billing',
|
||||
permissions: ['VIEW_INVOICES', 'CREATE_INVOICES', 'MANAGE_PAYMENTS']
|
||||
}
|
||||
permissions: ['TAB_BILLING_READ', 'TAB_BILLING_EDIT'],
|
||||
},
|
||||
{
|
||||
name: 'Reports',
|
||||
permissions: ['TAB_REPORTS_READ', 'TAB_REPORTS_EDIT'],
|
||||
},
|
||||
];
|
||||
|
||||
for (const feature of features) {
|
||||
@@ -109,7 +115,7 @@ async function main() {
|
||||
}
|
||||
console.log('✅ Created features and permissions');
|
||||
|
||||
console.log('🌱 Seeding completed successfully!'); ``
|
||||
console.log('🌱 Seeding completed successfully!');
|
||||
}
|
||||
|
||||
main()
|
||||
|
||||
@@ -7,6 +7,7 @@ import { AppService } from './app.service';
|
||||
import { AdminModule } from './admin/admin.module';
|
||||
import { PrismaModule } from '../prisma/prisma.module'; // ✅
|
||||
import { PatientsModule } from './modules/patients/patients.module';
|
||||
import { StaffModule } from './modules/staff/staff.module';
|
||||
|
||||
@Module({
|
||||
imports: [
|
||||
@@ -17,6 +18,7 @@ import { PatientsModule } from './modules/patients/patients.module';
|
||||
PrismaModule, // ✅ ADD THIS
|
||||
AuthModule,
|
||||
PatientsModule,
|
||||
StaffModule,
|
||||
AdminModule.forRoot(),
|
||||
],
|
||||
controllers: [AppController],
|
||||
|
||||
37
backend/src/common/permissions.spec.ts
Normal file
37
backend/src/common/permissions.spec.ts
Normal file
@@ -0,0 +1,37 @@
|
||||
import { isUnlimitedSeats, normalizeTabPermissions, SEAT_UNLIMITED_THRESHOLD } from './permissions';
|
||||
|
||||
describe('normalizeTabPermissions', () => {
|
||||
it('adds READ when EDIT is present', () => {
|
||||
expect(normalizeTabPermissions(['TAB_PATIENTS_EDIT'])).toEqual([
|
||||
'TAB_PATIENTS_READ',
|
||||
'TAB_PATIENTS_EDIT',
|
||||
]);
|
||||
});
|
||||
|
||||
it('dedupes and sorts', () => {
|
||||
expect(
|
||||
normalizeTabPermissions([
|
||||
'TAB_TODAY_READ',
|
||||
'TAB_TODAY_EDIT',
|
||||
'TAB_TODAY_READ',
|
||||
'bogus',
|
||||
]),
|
||||
).toEqual(['TAB_TODAY_READ', 'TAB_TODAY_EDIT']);
|
||||
});
|
||||
|
||||
it('accepts empty array', () => {
|
||||
expect(normalizeTabPermissions([])).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('isUnlimitedSeats', () => {
|
||||
it('treats sentinel as unlimited', () => {
|
||||
expect(isUnlimitedSeats(SEAT_UNLIMITED_THRESHOLD)).toBe(true);
|
||||
expect(isUnlimitedSeats(SEAT_UNLIMITED_THRESHOLD + 1)).toBe(true);
|
||||
});
|
||||
|
||||
it('treats normal caps as limited', () => {
|
||||
expect(isUnlimitedSeats(5)).toBe(false);
|
||||
expect(isUnlimitedSeats(15)).toBe(false);
|
||||
});
|
||||
});
|
||||
57
backend/src/common/permissions.ts
Normal file
57
backend/src/common/permissions.ts
Normal file
@@ -0,0 +1,57 @@
|
||||
/** Tab permissions — keep in sync with prisma seed and AuthService ALL_PERMISSIONS */
|
||||
export const ALL_TAB_PERMISSIONS = [
|
||||
'TAB_TODAY_READ',
|
||||
'TAB_TODAY_EDIT',
|
||||
'TAB_PATIENTS_READ',
|
||||
'TAB_PATIENTS_EDIT',
|
||||
'TAB_APPOINTMENTS_READ',
|
||||
'TAB_APPOINTMENTS_EDIT',
|
||||
'TAB_STAFF_READ',
|
||||
'TAB_STAFF_EDIT',
|
||||
'TAB_LAB_READ',
|
||||
'TAB_LAB_EDIT',
|
||||
'TAB_BILLING_READ',
|
||||
'TAB_BILLING_EDIT',
|
||||
'TAB_REPORTS_READ',
|
||||
'TAB_REPORTS_EDIT',
|
||||
] as const;
|
||||
|
||||
export type TabPermission = (typeof ALL_TAB_PERMISSIONS)[number];
|
||||
|
||||
const ALL_TAB_SET = new Set<string>(ALL_TAB_PERMISSIONS);
|
||||
const TAB_ORDER_INDEX = new Map<string, number>(
|
||||
ALL_TAB_PERMISSIONS.map((p, i) => [p, i]),
|
||||
);
|
||||
|
||||
/** Enterprise / unlimited seat plans use this sentinel in seed data */
|
||||
export const SEAT_UNLIMITED_THRESHOLD = 999999;
|
||||
|
||||
export function isUnlimitedSeats(maxUsers: number): boolean {
|
||||
return maxUsers >= SEAT_UNLIMITED_THRESHOLD;
|
||||
}
|
||||
|
||||
/** EDIT implies READ for the same feature tab */
|
||||
const EDIT_TO_READ: Record<string, string> = {
|
||||
TAB_TODAY_EDIT: 'TAB_TODAY_READ',
|
||||
TAB_PATIENTS_EDIT: 'TAB_PATIENTS_READ',
|
||||
TAB_APPOINTMENTS_EDIT: 'TAB_APPOINTMENTS_READ',
|
||||
TAB_STAFF_EDIT: 'TAB_STAFF_READ',
|
||||
TAB_LAB_EDIT: 'TAB_LAB_READ',
|
||||
TAB_BILLING_EDIT: 'TAB_BILLING_READ',
|
||||
TAB_REPORTS_EDIT: 'TAB_REPORTS_READ',
|
||||
};
|
||||
|
||||
/**
|
||||
* Dedupe, drop unknown strings, and add implied READ permissions for each EDIT.
|
||||
*/
|
||||
export function normalizeTabPermissions(names: string[]): string[] {
|
||||
const out = new Set<string>();
|
||||
for (const raw of names) {
|
||||
const n = typeof raw === 'string' ? raw.trim() : '';
|
||||
if (!n || !ALL_TAB_SET.has(n)) continue;
|
||||
out.add(n);
|
||||
const read = EDIT_TO_READ[n];
|
||||
if (read) out.add(read);
|
||||
}
|
||||
return [...out].sort((a, b) => (TAB_ORDER_INDEX.get(a) ?? 0) - (TAB_ORDER_INDEX.get(b) ?? 0));
|
||||
}
|
||||
@@ -25,6 +25,7 @@ import {
|
||||
import { AuthService } from './auth.service';
|
||||
import { LoginDto } from './dto/login.dto';
|
||||
import { RegisterDto } from './dto/register.dto';
|
||||
import { CreateOrganizationDto } from './dto/create-organization.dto';
|
||||
import { JwtAuthGuard } from './guards/jwt-auth.guard';
|
||||
import { LocalAuthGuard } from './guards/local-auth.guard';
|
||||
|
||||
@@ -120,6 +121,14 @@ export class AuthController {
|
||||
};
|
||||
}
|
||||
|
||||
@Post('organizations')
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiBearerAuth('JWT-auth')
|
||||
@ApiOperation({ summary: 'Create organization for current user' })
|
||||
async createOrganization(@Req() req, @Body() dto: CreateOrganizationDto) {
|
||||
return this.authService.createOrganization(req.user.id, dto);
|
||||
}
|
||||
|
||||
// =========================
|
||||
// PROFILE
|
||||
// =========================
|
||||
@@ -136,6 +145,20 @@ export class AuthController {
|
||||
return this.authService.getProfile(req.user.id);
|
||||
}
|
||||
|
||||
@Get('subscription-alert')
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiBearerAuth('JWT-auth')
|
||||
@ApiOperation({
|
||||
summary:
|
||||
'Owner-only: seat / trial status for warning indicator (current org from JWT)',
|
||||
})
|
||||
async getSubscriptionAlert(@Req() req) {
|
||||
return this.authService.getOwnerSubscriptionAlert(
|
||||
req.user.id,
|
||||
req.user.organizationId,
|
||||
);
|
||||
}
|
||||
|
||||
// =========================
|
||||
// LOGOUT
|
||||
// =========================
|
||||
|
||||
@@ -12,30 +12,24 @@ import * as bcrypt from 'bcrypt';
|
||||
import { PrismaService } from '../../../prisma/prisma.service';
|
||||
import { LoginDto } from './dto/login.dto';
|
||||
import { RegisterDto } from './dto/register.dto';
|
||||
import { CreateOrganizationDto } from './dto/create-organization.dto';
|
||||
import { JwtPayload } from './interfaces/jwt-payload.interface';
|
||||
|
||||
const ALL_PERMISSIONS = [
|
||||
'VIEW_PATIENTS',
|
||||
'CREATE_PATIENTS',
|
||||
'EDIT_PATIENTS',
|
||||
'DELETE_PATIENTS',
|
||||
'VIEW_ORDERS',
|
||||
'CREATE_ORDERS',
|
||||
'EDIT_ORDERS',
|
||||
'DELETE_ORDERS',
|
||||
'TRACK_ORDERS',
|
||||
'VIEW_CASES',
|
||||
'CREATE_CASES',
|
||||
'EDIT_CASES',
|
||||
'DELETE_CASES',
|
||||
'VIEW_REPORTS',
|
||||
'EXPORT_REPORTS',
|
||||
'INVITE_USERS',
|
||||
'REMOVE_USERS',
|
||||
'MANAGE_PERMISSIONS',
|
||||
'VIEW_INVOICES',
|
||||
'CREATE_INVOICES',
|
||||
'MANAGE_PAYMENTS',
|
||||
'TAB_TODAY_READ',
|
||||
'TAB_TODAY_EDIT',
|
||||
'TAB_PATIENTS_READ',
|
||||
'TAB_PATIENTS_EDIT',
|
||||
'TAB_APPOINTMENTS_READ',
|
||||
'TAB_APPOINTMENTS_EDIT',
|
||||
'TAB_STAFF_READ',
|
||||
'TAB_STAFF_EDIT',
|
||||
'TAB_LAB_READ',
|
||||
'TAB_LAB_EDIT',
|
||||
'TAB_BILLING_READ',
|
||||
'TAB_BILLING_EDIT',
|
||||
'TAB_REPORTS_READ',
|
||||
'TAB_REPORTS_EDIT',
|
||||
];
|
||||
|
||||
@Injectable()
|
||||
@@ -54,14 +48,16 @@ export class AuthService {
|
||||
*/
|
||||
async validateUser(email: string, password: string): Promise<any> {
|
||||
try {
|
||||
const normalizedEmail = email.trim().toLowerCase();
|
||||
const user = await this.prisma.user.findUnique({
|
||||
where: { email },
|
||||
where: { email: normalizedEmail },
|
||||
include: {
|
||||
memberships: {
|
||||
include: {
|
||||
organization: {
|
||||
include: {
|
||||
type: true, // Include organization type (CLINIC/LAB)
|
||||
plan: true,
|
||||
}
|
||||
},
|
||||
permissions: {
|
||||
@@ -140,7 +136,7 @@ export class AuthService {
|
||||
});
|
||||
|
||||
// Transform memberships to include organization info and permissions
|
||||
const organizations = user.memberships?.map(membership => ({
|
||||
const organizations = this.toActiveOrganizations(user.memberships).map(membership => ({
|
||||
id: membership.organization.id,
|
||||
name: membership.organization.name,
|
||||
type: membership.organization.type.name, // 'CLINIC' or 'LAB'
|
||||
@@ -148,7 +144,14 @@ export class AuthService {
|
||||
permissions: membership.isOwner
|
||||
? ALL_PERMISSIONS
|
||||
: membership.permissions?.map(p => p.permission.name) || [],
|
||||
})) || [];
|
||||
plan: membership.organization.plan
|
||||
? {
|
||||
name: membership.organization.plan.name,
|
||||
maxUsers: membership.organization.plan.maxUsers,
|
||||
price: membership.organization.plan.price,
|
||||
}
|
||||
: undefined,
|
||||
}));
|
||||
|
||||
return {
|
||||
success: true,
|
||||
@@ -176,7 +179,8 @@ export class AuthService {
|
||||
* @returns Created user info without password
|
||||
*/
|
||||
async register(registerDto: RegisterDto) {
|
||||
const { email, password, name, organizationName, organizationType } = registerDto;
|
||||
const { password, name, organizationName, organizationEmail, organizationType } = registerDto;
|
||||
const email = registerDto.email.trim().toLowerCase();
|
||||
|
||||
// 1. Check existing user
|
||||
const existingUser = await this.prisma.user.findUnique({
|
||||
@@ -184,7 +188,7 @@ export class AuthService {
|
||||
});
|
||||
|
||||
if (existingUser) {
|
||||
throw new ConflictException('User already exists');
|
||||
throw new ConflictException('User already exists. Please login and create a new organization from your account.');
|
||||
}
|
||||
|
||||
// 2. Hash password
|
||||
@@ -198,16 +202,15 @@ export class AuthService {
|
||||
email,
|
||||
passwordHash: hashedPassword,
|
||||
name,
|
||||
trialUsedAt: new Date(),
|
||||
},
|
||||
});
|
||||
|
||||
// Create organization
|
||||
const organization = await tx.organization.create({
|
||||
data: {
|
||||
name: registerDto.organizationName,
|
||||
|
||||
// REQUIRED FIELDS 👇
|
||||
email: registerDto.email, // or separate org email if you have one
|
||||
name: organizationName,
|
||||
email: organizationEmail,
|
||||
|
||||
owner: {
|
||||
connect: { id: user.id },
|
||||
@@ -219,7 +222,7 @@ export class AuthService {
|
||||
|
||||
type: {
|
||||
connect: {
|
||||
name: registerDto.organizationType, // 'CLINIC' | 'LAB'
|
||||
name: organizationType, // 'CLINIC' | 'LAB'
|
||||
},
|
||||
},
|
||||
},
|
||||
@@ -247,6 +250,66 @@ export class AuthService {
|
||||
return this.login({ email, password } as any, validatedUser);
|
||||
}
|
||||
|
||||
async createOrganization(userId: string, dto: CreateOrganizationDto) {
|
||||
const owner = await this.prisma.user.findUnique({
|
||||
where: { id: userId },
|
||||
select: { id: true, trialUsedAt: true },
|
||||
});
|
||||
|
||||
if (!owner) {
|
||||
throw new UnauthorizedException('User not found');
|
||||
}
|
||||
|
||||
const planName = dto.planName?.trim() || 'Small';
|
||||
const effectivePlanName = owner.trialUsedAt ? planName : 'trial';
|
||||
|
||||
const organization = await this.prisma.$transaction(async (tx) => {
|
||||
const createdOrganization = await tx.organization.create({
|
||||
data: {
|
||||
name: dto.organizationName,
|
||||
email: dto.organizationEmail,
|
||||
owner: {
|
||||
connect: { id: userId },
|
||||
},
|
||||
plan: {
|
||||
connect: { name: effectivePlanName },
|
||||
},
|
||||
type: {
|
||||
connect: { name: dto.organizationType },
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
await tx.membership.create({
|
||||
data: {
|
||||
userId,
|
||||
organizationId: createdOrganization.id,
|
||||
isOwner: true,
|
||||
},
|
||||
});
|
||||
|
||||
if (!owner.trialUsedAt) {
|
||||
await tx.user.update({
|
||||
where: { id: userId },
|
||||
data: { trialUsedAt: new Date() },
|
||||
});
|
||||
}
|
||||
|
||||
return createdOrganization;
|
||||
});
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
organization: {
|
||||
id: organization.id,
|
||||
name: organization.name,
|
||||
email: organization.email,
|
||||
},
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Get user profile with all memberships and permissions
|
||||
* @param userId - User ID from JWT token
|
||||
@@ -262,6 +325,7 @@ export class AuthService {
|
||||
organization: {
|
||||
include: {
|
||||
type: true,
|
||||
plan: true,
|
||||
},
|
||||
},
|
||||
permissions: {
|
||||
@@ -281,13 +345,22 @@ export class AuthService {
|
||||
const { passwordHash, ...result } = user;
|
||||
|
||||
// Transform memberships for frontend consumption
|
||||
const organizations = user.memberships?.map(membership => ({
|
||||
const organizations = this.toActiveOrganizations(user.memberships).map(membership => ({
|
||||
id: membership.organization.id,
|
||||
name: membership.organization.name,
|
||||
type: membership.organization.type.name,
|
||||
isOwner: membership.isOwner,
|
||||
permissions: membership.permissions?.map(p => p.permission.name) || [],
|
||||
})) || [];
|
||||
permissions: membership.isOwner
|
||||
? ALL_PERMISSIONS
|
||||
: membership.permissions?.map(p => p.permission.name) || [],
|
||||
plan: membership.organization.plan
|
||||
? {
|
||||
name: membership.organization.plan.name,
|
||||
maxUsers: membership.organization.plan.maxUsers,
|
||||
price: membership.organization.plan.price,
|
||||
}
|
||||
: undefined,
|
||||
}));
|
||||
|
||||
return {
|
||||
success: true,
|
||||
@@ -352,6 +425,7 @@ export class AuthService {
|
||||
organization: {
|
||||
include: {
|
||||
type: true,
|
||||
plan: true,
|
||||
},
|
||||
},
|
||||
permissions: {
|
||||
@@ -392,13 +466,22 @@ export class AuthService {
|
||||
});
|
||||
|
||||
// Transform memberships for response
|
||||
const organizations = session.user.memberships?.map(membership => ({
|
||||
const organizations = this.toActiveOrganizations(session.user.memberships).map(membership => ({
|
||||
id: membership.organization.id,
|
||||
name: membership.organization.name,
|
||||
type: membership.organization.type.name,
|
||||
isOwner: membership.isOwner,
|
||||
permissions: membership.permissions?.map(p => p.permission.name) || [],
|
||||
})) || [];
|
||||
permissions: membership.isOwner
|
||||
? ALL_PERMISSIONS
|
||||
: membership.permissions?.map(p => p.permission.name) || [],
|
||||
plan: membership.organization.plan
|
||||
? {
|
||||
name: membership.organization.plan.name,
|
||||
maxUsers: membership.organization.plan.maxUsers,
|
||||
price: membership.organization.plan.price,
|
||||
}
|
||||
: undefined,
|
||||
}));
|
||||
|
||||
return {
|
||||
success: true,
|
||||
@@ -569,6 +652,7 @@ export class AuthService {
|
||||
organization: {
|
||||
include: {
|
||||
type: true,
|
||||
plan: true,
|
||||
},
|
||||
},
|
||||
permissions: {
|
||||
@@ -589,13 +673,22 @@ export class AuthService {
|
||||
|
||||
const { passwordHash, ...user } = session.user;
|
||||
|
||||
const organizations = session.user.memberships?.map(membership => ({
|
||||
const organizations = this.toActiveOrganizations(session.user.memberships).map(membership => ({
|
||||
id: membership.organization.id,
|
||||
name: membership.organization.name,
|
||||
type: membership.organization.type.name,
|
||||
isOwner: membership.isOwner,
|
||||
permissions: membership.permissions?.map(p => p.permission.name) || [],
|
||||
})) || [];
|
||||
permissions: membership.isOwner
|
||||
? ALL_PERMISSIONS
|
||||
: membership.permissions?.map(p => p.permission.name) || [],
|
||||
plan: membership.organization.plan
|
||||
? {
|
||||
name: membership.organization.plan.name,
|
||||
maxUsers: membership.organization.plan.maxUsers,
|
||||
price: membership.organization.plan.price,
|
||||
}
|
||||
: undefined,
|
||||
}));
|
||||
|
||||
return {
|
||||
success: true,
|
||||
@@ -617,6 +710,7 @@ export class AuthService {
|
||||
organizationId,
|
||||
},
|
||||
include: {
|
||||
user: true,
|
||||
organization: {
|
||||
include: {
|
||||
type: true,
|
||||
@@ -634,11 +728,14 @@ export class AuthService {
|
||||
if (!membership) {
|
||||
throw new UnauthorizedException('Access denied to this organization');
|
||||
}
|
||||
if (!membership.isOwner && !membership.isActive) {
|
||||
throw new UnauthorizedException('Your invitation is still pending activation');
|
||||
}
|
||||
|
||||
// 2. Build payload WITH org context
|
||||
const payload = {
|
||||
sub: userId,
|
||||
email: membership.organization.email,
|
||||
email: membership.user.email,
|
||||
organizationId: membership.organizationId,
|
||||
type: 'access',
|
||||
};
|
||||
@@ -650,7 +747,9 @@ export class AuthService {
|
||||
});
|
||||
|
||||
// 4. Format permissions
|
||||
const permissions = membership.permissions.map(p => p.permission.name);
|
||||
const permissions = membership.isOwner
|
||||
? ALL_PERMISSIONS
|
||||
: membership.permissions.map(p => p.permission.name);
|
||||
|
||||
return {
|
||||
success: true,
|
||||
@@ -660,8 +759,119 @@ export class AuthService {
|
||||
id: membership.organization.id,
|
||||
name: membership.organization.name,
|
||||
type: membership.organization.type.name,
|
||||
isOwner: membership.isOwner,
|
||||
permissions,
|
||||
plan: membership.organization.plan
|
||||
? {
|
||||
name: membership.organization.plan.name,
|
||||
maxUsers: membership.organization.plan.maxUsers,
|
||||
price: membership.organization.plan.price,
|
||||
}
|
||||
: undefined,
|
||||
},
|
||||
permissions,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
private toActiveOrganizations(
|
||||
memberships: Array<{
|
||||
isOwner: boolean;
|
||||
isActive: boolean;
|
||||
organization: {
|
||||
id: string;
|
||||
name: string;
|
||||
type: { name: string };
|
||||
plan?: { name: string; maxUsers: number; price: number } | null;
|
||||
};
|
||||
permissions?: Array<{ permission: { name: string } }>;
|
||||
}> = [],
|
||||
) {
|
||||
return memberships.filter((m) => m.isOwner || m.isActive);
|
||||
}
|
||||
|
||||
/**
|
||||
* Owner-only subscription / seat alerts for the current org (from JWT).
|
||||
* Used for a subtle warning indicator in the app shell (not staff-facing banners).
|
||||
*/
|
||||
async getOwnerSubscriptionAlert(userId: string, organizationId: string | undefined) {
|
||||
if (!organizationId) {
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
showWarning: false,
|
||||
seatsLow: false,
|
||||
trialEndingSoon: false,
|
||||
trialExpired: false,
|
||||
daysUntilPlanEnd: null,
|
||||
planEndsAt: null,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
const membership = await this.prisma.membership.findFirst({
|
||||
where: { userId, organizationId },
|
||||
include: {
|
||||
organization: {
|
||||
include: { plan: true },
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
if (!membership || !membership.isOwner) {
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
showWarning: false,
|
||||
seatsLow: false,
|
||||
trialEndingSoon: false,
|
||||
trialExpired: false,
|
||||
daysUntilPlanEnd: null,
|
||||
planEndsAt: null,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
const org = membership.organization;
|
||||
const plan = org.plan;
|
||||
const maxUsers = plan.maxUsers;
|
||||
const seatsUsed = await this.prisma.membership.count({
|
||||
where: {
|
||||
organizationId: org.id,
|
||||
OR: [{ isOwner: true }, { isActive: true }],
|
||||
},
|
||||
});
|
||||
|
||||
const unlimited = maxUsers >= 999999;
|
||||
const remaining = unlimited ? Infinity : maxUsers - seatsUsed;
|
||||
const seatsLow =
|
||||
!unlimited && remaining >= 0 && remaining <= 2 && maxUsers > 0;
|
||||
|
||||
// Current pricing model: trial lasts 30 days; paid plans last 90 days.
|
||||
const durationDays = plan.name === 'trial' ? 30 : 90;
|
||||
const end = new Date(org.createdAt);
|
||||
end.setDate(end.getDate() + durationDays);
|
||||
const planEndsAt = end.toISOString();
|
||||
const ms = end.getTime() - Date.now();
|
||||
const daysUntilPlanEnd = Math.ceil(ms / (1000 * 60 * 60 * 24));
|
||||
|
||||
const trialExpired = plan.name === 'trial' && daysUntilPlanEnd <= 0;
|
||||
const trialEndingSoon = plan.name === 'trial' && daysUntilPlanEnd > 0 && daysUntilPlanEnd <= 7;
|
||||
|
||||
const showWarning = seatsLow || trialEndingSoon || trialExpired;
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
showWarning,
|
||||
seatsLow,
|
||||
trialEndingSoon,
|
||||
trialExpired,
|
||||
seatsUsed,
|
||||
seatsLimit: maxUsers,
|
||||
daysUntilTrialEnd: plan.name === 'trial' ? daysUntilPlanEnd : null,
|
||||
trialEndsAt: plan.name === 'trial' ? planEndsAt : null,
|
||||
daysUntilPlanEnd,
|
||||
planEndsAt,
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
16
backend/src/modules/auth/dto/create-organization.dto.ts
Normal file
16
backend/src/modules/auth/dto/create-organization.dto.ts
Normal file
@@ -0,0 +1,16 @@
|
||||
import { IsEmail, IsEnum, IsOptional, IsString } from 'class-validator';
|
||||
|
||||
export class CreateOrganizationDto {
|
||||
@IsString()
|
||||
organizationName: string;
|
||||
|
||||
@IsEmail()
|
||||
organizationEmail: string;
|
||||
|
||||
@IsEnum(['CLINIC', 'LAB'])
|
||||
organizationType: 'CLINIC' | 'LAB';
|
||||
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
planName?: string;
|
||||
}
|
||||
@@ -14,6 +14,9 @@ export class RegisterDto {
|
||||
@IsString()
|
||||
organizationName: string;
|
||||
|
||||
@IsEmail()
|
||||
organizationEmail: string;
|
||||
|
||||
@IsEnum(['CLINIC', 'LAB'])
|
||||
organizationType: 'CLINIC' | 'LAB';
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
export interface JwtPayload {
|
||||
sub: string; // user id
|
||||
email: string;
|
||||
organizationId?: string;
|
||||
type?: 'access' | 'refresh';
|
||||
}
|
||||
|
||||
|
||||
14
backend/src/modules/staff/dto/accept-staff-invite.dto.ts
Normal file
14
backend/src/modules/staff/dto/accept-staff-invite.dto.ts
Normal file
@@ -0,0 +1,14 @@
|
||||
import { IsString, MinLength } from 'class-validator';
|
||||
|
||||
export class AcceptStaffInviteDto {
|
||||
@IsString()
|
||||
token: string;
|
||||
|
||||
@IsString()
|
||||
@MinLength(8)
|
||||
password: string;
|
||||
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name: string;
|
||||
}
|
||||
15
backend/src/modules/staff/dto/invite-staff.dto.ts
Normal file
15
backend/src/modules/staff/dto/invite-staff.dto.ts
Normal file
@@ -0,0 +1,15 @@
|
||||
import { IsArray, IsEmail, IsString, MinLength } from 'class-validator';
|
||||
|
||||
export class InviteStaffDto {
|
||||
@IsEmail()
|
||||
email: string;
|
||||
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name: string;
|
||||
|
||||
/** TAB_* permission names; EDIT implies READ after normalization. */
|
||||
@IsArray()
|
||||
@IsString({ each: true })
|
||||
permissionNames: string[];
|
||||
}
|
||||
@@ -0,0 +1,6 @@
|
||||
import { IsString } from 'class-validator';
|
||||
|
||||
export class PreviewStaffInviteDto {
|
||||
@IsString()
|
||||
token: string;
|
||||
}
|
||||
13
backend/src/modules/staff/dto/update-staff-member.dto.ts
Normal file
13
backend/src/modules/staff/dto/update-staff-member.dto.ts
Normal file
@@ -0,0 +1,13 @@
|
||||
import { IsArray, IsOptional, IsString, MinLength } from 'class-validator';
|
||||
|
||||
export class UpdateStaffMemberDto {
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsArray()
|
||||
@IsString({ each: true })
|
||||
permissionNames?: string[];
|
||||
}
|
||||
80
backend/src/modules/staff/staff.controller.ts
Normal file
80
backend/src/modules/staff/staff.controller.ts
Normal file
@@ -0,0 +1,80 @@
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Query,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from '@nestjs/common';
|
||||
import { ApiBearerAuth, ApiOperation, ApiTags } from '@nestjs/swagger';
|
||||
import { JwtAuthGuard } from '../auth/guards/jwt-auth.guard';
|
||||
import { AcceptStaffInviteDto } from './dto/accept-staff-invite.dto';
|
||||
import { InviteStaffDto } from './dto/invite-staff.dto';
|
||||
import { PreviewStaffInviteDto } from './dto/preview-staff-invite.dto';
|
||||
import { UpdateStaffMemberDto } from './dto/update-staff-member.dto';
|
||||
import { StaffService } from './staff.service';
|
||||
|
||||
@ApiTags('staff')
|
||||
@ApiBearerAuth('JWT-auth')
|
||||
@Controller('staff')
|
||||
export class StaffController {
|
||||
constructor(private readonly staffService: StaffService) {}
|
||||
|
||||
@Get('invitations/preview')
|
||||
@ApiOperation({ summary: 'Preview invite info by token (public)' })
|
||||
previewInvite(@Query() query: PreviewStaffInviteDto) {
|
||||
return this.staffService.previewInvite(query.token);
|
||||
}
|
||||
|
||||
@Post('invitations/accept')
|
||||
@ApiOperation({ summary: 'Accept invite and activate account (public)' })
|
||||
acceptInvite(@Body() dto: AcceptStaffInviteDto) {
|
||||
return this.staffService.acceptInvite(dto);
|
||||
}
|
||||
|
||||
@Get()
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiOperation({ summary: 'List organization members (requires TAB_STAFF_READ or owner)' })
|
||||
list(@Req() req: { user: { id: string; organizationId?: string } }) {
|
||||
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||
return this.staffService.list(req.user.id, organizationId);
|
||||
}
|
||||
|
||||
@Post('invite')
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiOperation({ summary: 'Invite staff (requires TAB_STAFF_EDIT or owner)' })
|
||||
invite(
|
||||
@Req() req: { user: { id: string; organizationId?: string } },
|
||||
@Body() dto: InviteStaffDto,
|
||||
) {
|
||||
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||
return this.staffService.invite(req.user.id, organizationId, dto);
|
||||
}
|
||||
|
||||
@Patch('members/:membershipId')
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiOperation({ summary: 'Update staff member name and/or permissions' })
|
||||
updateMember(
|
||||
@Req() req: { user: { id: string; organizationId?: string } },
|
||||
@Param('membershipId') membershipId: string,
|
||||
@Body() dto: UpdateStaffMemberDto,
|
||||
) {
|
||||
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||
return this.staffService.updateMember(req.user.id, organizationId, membershipId, dto);
|
||||
}
|
||||
|
||||
@Delete('members/:membershipId')
|
||||
@UseGuards(JwtAuthGuard)
|
||||
@ApiOperation({ summary: 'Remove staff member from organization' })
|
||||
removeMember(
|
||||
@Req() req: { user: { id: string; organizationId?: string } },
|
||||
@Param('membershipId') membershipId: string,
|
||||
) {
|
||||
const organizationId = this.staffService.getOrganizationIdFromUser(req.user);
|
||||
return this.staffService.removeMember(req.user.id, organizationId, membershipId);
|
||||
}
|
||||
}
|
||||
10
backend/src/modules/staff/staff.module.ts
Normal file
10
backend/src/modules/staff/staff.module.ts
Normal file
@@ -0,0 +1,10 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { PrismaService } from '../../../prisma/prisma.service';
|
||||
import { StaffController } from './staff.controller';
|
||||
import { StaffService } from './staff.service';
|
||||
|
||||
@Module({
|
||||
controllers: [StaffController],
|
||||
providers: [StaffService, PrismaService],
|
||||
})
|
||||
export class StaffModule {}
|
||||
443
backend/src/modules/staff/staff.service.ts
Normal file
443
backend/src/modules/staff/staff.service.ts
Normal file
@@ -0,0 +1,443 @@
|
||||
import {
|
||||
BadRequestException,
|
||||
ConflictException,
|
||||
ForbiddenException,
|
||||
Injectable,
|
||||
NotFoundException,
|
||||
} from '@nestjs/common';
|
||||
import * as bcrypt from 'bcrypt';
|
||||
import { createHash, randomBytes } from 'crypto';
|
||||
import { PrismaService } from '../../../prisma/prisma.service';
|
||||
import { AcceptStaffInviteDto } from './dto/accept-staff-invite.dto';
|
||||
import { isUnlimitedSeats, normalizeTabPermissions } from '../../common/permissions';
|
||||
import { InviteStaffDto } from './dto/invite-staff.dto';
|
||||
import { UpdateStaffMemberDto } from './dto/update-staff-member.dto';
|
||||
|
||||
@Injectable()
|
||||
export class StaffService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
getOrganizationIdFromUser(user: { organizationId?: string }) {
|
||||
if (!user?.organizationId) {
|
||||
throw new BadRequestException('Organization is not selected');
|
||||
}
|
||||
return user.organizationId;
|
||||
}
|
||||
|
||||
async list(userId: string, organizationId: string) {
|
||||
const actor = await this.getActorMembership(userId, organizationId);
|
||||
if (!actor || !this.canViewStaff(actor)) {
|
||||
throw new ForbiddenException('You do not have access to staff management');
|
||||
}
|
||||
|
||||
const org = await this.prisma.organization.findUnique({
|
||||
where: { id: organizationId },
|
||||
include: { plan: true },
|
||||
});
|
||||
if (!org) {
|
||||
throw new NotFoundException('Organization not found');
|
||||
}
|
||||
|
||||
const [members, seatsUsed] = await Promise.all([
|
||||
this.prisma.membership.findMany({
|
||||
where: { organizationId },
|
||||
include: {
|
||||
user: { select: { id: true, email: true, name: true } },
|
||||
permissions: { include: { permission: true } },
|
||||
invitations: {
|
||||
orderBy: { createdAt: 'desc' },
|
||||
take: 1,
|
||||
},
|
||||
},
|
||||
orderBy: [{ isOwner: 'desc' }, { createdAt: 'asc' }],
|
||||
}),
|
||||
this.prisma.membership.count({
|
||||
where: {
|
||||
organizationId,
|
||||
OR: [{ isOwner: true }, { isActive: true }],
|
||||
},
|
||||
}),
|
||||
]);
|
||||
|
||||
const maxUsers = org.plan.maxUsers;
|
||||
const unlimited = isUnlimitedSeats(maxUsers);
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
members: members.map((m) => ({
|
||||
id: m.id,
|
||||
userId: m.user.id,
|
||||
email: m.user.email,
|
||||
name: m.user.name,
|
||||
isOwner: m.isOwner,
|
||||
isActive: m.isOwner ? true : m.isActive,
|
||||
invitationStatus: this.getInvitationStatus(m),
|
||||
invitedAt: m.invitations[0]?.createdAt?.toISOString() || null,
|
||||
acceptedAt: m.invitations[0]?.acceptedAt?.toISOString() || null,
|
||||
permissions: m.isOwner
|
||||
? null
|
||||
: m.permissions.map((p) => p.permission.name),
|
||||
})),
|
||||
seats: {
|
||||
used: seatsUsed,
|
||||
limit: unlimited ? null : maxUsers,
|
||||
unlimited,
|
||||
},
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
async invite(userId: string, organizationId: string, dto: InviteStaffDto) {
|
||||
const actor = await this.getActorMembership(userId, organizationId);
|
||||
if (!actor || !this.canEditStaff(actor)) {
|
||||
throw new ForbiddenException('You cannot invite or manage staff');
|
||||
}
|
||||
|
||||
const email = dto.email.trim().toLowerCase();
|
||||
const normalizedPerms = normalizeTabPermissions(dto.permissionNames);
|
||||
|
||||
const permissionRows = await this.prisma.permission.findMany({
|
||||
where: { name: { in: normalizedPerms } },
|
||||
select: { id: true, name: true },
|
||||
});
|
||||
if (permissionRows.length !== normalizedPerms.length) {
|
||||
const ok = new Set(permissionRows.map((p) => p.name));
|
||||
const missing = normalizedPerms.filter((n) => !ok.has(n));
|
||||
throw new BadRequestException(`Unknown or invalid permissions: ${missing.join(', ')}`);
|
||||
}
|
||||
|
||||
const plainToken = this.generateInviteToken();
|
||||
const tokenHash = this.hashInviteToken(plainToken);
|
||||
|
||||
const result = await this.prisma.$transaction(async (tx) => {
|
||||
const org = await tx.organization.findUnique({
|
||||
where: { id: organizationId },
|
||||
include: { plan: true },
|
||||
});
|
||||
if (!org) {
|
||||
throw new NotFoundException('Organization not found');
|
||||
}
|
||||
|
||||
const maxUsers = org.plan.maxUsers;
|
||||
const seatsUsed = await tx.membership.count({
|
||||
where: {
|
||||
organizationId,
|
||||
OR: [{ isOwner: true }, { isActive: true }],
|
||||
},
|
||||
});
|
||||
if (!isUnlimitedSeats(maxUsers) && seatsUsed >= maxUsers) {
|
||||
throw new BadRequestException(
|
||||
`Your plan allows ${maxUsers} team members. Remove a member or upgrade to add more.`,
|
||||
);
|
||||
}
|
||||
|
||||
const existingUser = await tx.user.findUnique({ where: { email } });
|
||||
let targetUserId: string;
|
||||
|
||||
if (existingUser) {
|
||||
if (existingUser.id === org.ownerId) {
|
||||
throw new BadRequestException('Organization owner is already a member');
|
||||
}
|
||||
const dup = await tx.membership.findUnique({
|
||||
where: {
|
||||
userId_organizationId: {
|
||||
userId: existingUser.id,
|
||||
organizationId,
|
||||
},
|
||||
},
|
||||
});
|
||||
if (dup) {
|
||||
throw new ConflictException('This user is already a member of this organization');
|
||||
}
|
||||
targetUserId = existingUser.id;
|
||||
} else {
|
||||
const created = await tx.user.create({
|
||||
data: {
|
||||
email,
|
||||
name: dto.name.trim(),
|
||||
passwordHash: null,
|
||||
},
|
||||
});
|
||||
targetUserId = created.id;
|
||||
}
|
||||
|
||||
const membership = await tx.membership.create({
|
||||
data: {
|
||||
userId: targetUserId,
|
||||
organizationId,
|
||||
isOwner: false,
|
||||
isActive: existingUser ? true : false,
|
||||
},
|
||||
});
|
||||
|
||||
if (permissionRows.length > 0) {
|
||||
await tx.membershipPermission.createMany({
|
||||
data: permissionRows.map((p) => ({
|
||||
membershipId: membership.id,
|
||||
permissionId: p.id,
|
||||
})),
|
||||
});
|
||||
}
|
||||
|
||||
let inviteUrl: string | null = null;
|
||||
let invitationId: string | null = null;
|
||||
|
||||
if (!existingUser) {
|
||||
const invitation = await tx.staffInvitation.create({
|
||||
data: {
|
||||
membershipId: membership.id,
|
||||
invitedById: userId,
|
||||
tokenHash,
|
||||
expiresAt: this.getInviteExpiryDate(),
|
||||
},
|
||||
});
|
||||
invitationId = invitation.id;
|
||||
inviteUrl = this.buildInviteUrl(plainToken);
|
||||
}
|
||||
|
||||
return {
|
||||
membershipId: membership.id,
|
||||
userId: targetUserId,
|
||||
invitationId,
|
||||
inviteUrl,
|
||||
isPending: !existingUser,
|
||||
};
|
||||
});
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
membershipId: result.membershipId,
|
||||
userId: result.userId,
|
||||
email,
|
||||
invitationId: result.invitationId,
|
||||
invitationUrl: result.inviteUrl,
|
||||
invitationStatus: result.isPending ? 'PENDING' : 'ACCEPTED',
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
async previewInvite(token: string) {
|
||||
const invitation = await this.findValidInvitation(token);
|
||||
const org = invitation.membership.organization;
|
||||
const user = invitation.membership.user;
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
email: user.email,
|
||||
name: user.name,
|
||||
organizationName: org.name,
|
||||
expiresAt: invitation.expiresAt.toISOString(),
|
||||
status: invitation.acceptedAt ? 'ACCEPTED' : 'PENDING',
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
async acceptInvite(dto: AcceptStaffInviteDto) {
|
||||
const invitation = await this.findValidInvitation(dto.token);
|
||||
|
||||
if (invitation.acceptedAt) {
|
||||
throw new BadRequestException('This invitation has already been accepted');
|
||||
}
|
||||
|
||||
const passwordHash = await bcrypt.hash(dto.password, 10);
|
||||
const now = new Date();
|
||||
|
||||
await this.prisma.$transaction(async (tx) => {
|
||||
await tx.user.update({
|
||||
where: { id: invitation.membership.userId },
|
||||
data: {
|
||||
passwordHash,
|
||||
name: dto.name.trim(),
|
||||
},
|
||||
});
|
||||
|
||||
await tx.membership.update({
|
||||
where: { id: invitation.membershipId },
|
||||
data: { isActive: true },
|
||||
});
|
||||
|
||||
await tx.staffInvitation.update({
|
||||
where: { id: invitation.id },
|
||||
data: { acceptedAt: now },
|
||||
});
|
||||
});
|
||||
|
||||
return {
|
||||
success: true,
|
||||
data: {
|
||||
email: invitation.membership.user.email,
|
||||
},
|
||||
message: 'Invitation accepted. You can now log in.',
|
||||
};
|
||||
}
|
||||
|
||||
async updateMember(
|
||||
actorUserId: string,
|
||||
organizationId: string,
|
||||
membershipId: string,
|
||||
dto: UpdateStaffMemberDto,
|
||||
) {
|
||||
const actor = await this.getActorMembership(actorUserId, organizationId);
|
||||
if (!actor || !this.canEditStaff(actor)) {
|
||||
throw new ForbiddenException('You cannot edit staff');
|
||||
}
|
||||
|
||||
const target = await this.prisma.membership.findFirst({
|
||||
where: { id: membershipId, organizationId },
|
||||
include: {
|
||||
user: true,
|
||||
permissions: { include: { permission: true } },
|
||||
},
|
||||
});
|
||||
|
||||
if (!target) {
|
||||
throw new NotFoundException('Member not found');
|
||||
}
|
||||
if (target.isOwner) {
|
||||
throw new ForbiddenException('Owner membership cannot be edited here');
|
||||
}
|
||||
|
||||
if (dto.name !== undefined) {
|
||||
await this.prisma.user.update({
|
||||
where: { id: target.userId },
|
||||
data: { name: dto.name.trim() },
|
||||
});
|
||||
}
|
||||
|
||||
if (dto.permissionNames !== undefined) {
|
||||
const normalizedPerms = normalizeTabPermissions(dto.permissionNames);
|
||||
const permissionRows = await this.prisma.permission.findMany({
|
||||
where: { name: { in: normalizedPerms } },
|
||||
select: { id: true, name: true },
|
||||
});
|
||||
if (permissionRows.length !== normalizedPerms.length) {
|
||||
const ok = new Set(permissionRows.map((p) => p.name));
|
||||
const missing = normalizedPerms.filter((n) => !ok.has(n));
|
||||
throw new BadRequestException(`Unknown or invalid permissions: ${missing.join(', ')}`);
|
||||
}
|
||||
|
||||
await this.prisma.$transaction([
|
||||
this.prisma.membershipPermission.deleteMany({ where: { membershipId: target.id } }),
|
||||
...(permissionRows.length
|
||||
? [
|
||||
this.prisma.membershipPermission.createMany({
|
||||
data: permissionRows.map((p) => ({
|
||||
membershipId: target.id,
|
||||
permissionId: p.id,
|
||||
})),
|
||||
}),
|
||||
]
|
||||
: []),
|
||||
]);
|
||||
}
|
||||
|
||||
return { success: true, message: 'Member updated' };
|
||||
}
|
||||
|
||||
async removeMember(actorUserId: string, organizationId: string, membershipId: string) {
|
||||
const actor = await this.getActorMembership(actorUserId, organizationId);
|
||||
if (!actor || !this.canEditStaff(actor)) {
|
||||
throw new ForbiddenException('You cannot remove staff');
|
||||
}
|
||||
|
||||
const target = await this.prisma.membership.findFirst({
|
||||
where: { id: membershipId, organizationId },
|
||||
});
|
||||
|
||||
if (!target) {
|
||||
throw new NotFoundException('Member not found');
|
||||
}
|
||||
if (target.isOwner) {
|
||||
throw new ForbiddenException('Cannot remove the organization owner');
|
||||
}
|
||||
|
||||
await this.prisma.membership.delete({ where: { id: membershipId } });
|
||||
|
||||
return { success: true, message: 'Member removed' };
|
||||
}
|
||||
|
||||
private async getActorMembership(userId: string, organizationId: string) {
|
||||
return this.prisma.membership.findFirst({
|
||||
where: { userId, organizationId },
|
||||
include: { permissions: { include: { permission: true } } },
|
||||
});
|
||||
}
|
||||
|
||||
private getInvitationStatus(m: {
|
||||
isOwner: boolean;
|
||||
isActive: boolean;
|
||||
invitations: { acceptedAt: Date | null; revokedAt: Date | null; expiresAt: Date }[];
|
||||
}): 'ACTIVE' | 'PENDING' | 'EXPIRED' {
|
||||
if (m.isOwner || m.isActive) return 'ACTIVE';
|
||||
const invitation = m.invitations[0];
|
||||
if (!invitation) return 'EXPIRED';
|
||||
if (invitation.acceptedAt || invitation.revokedAt) return 'ACTIVE';
|
||||
return invitation.expiresAt.getTime() > Date.now() ? 'PENDING' : 'EXPIRED';
|
||||
}
|
||||
|
||||
private generateInviteToken(): string {
|
||||
return randomBytes(32).toString('hex');
|
||||
}
|
||||
|
||||
private hashInviteToken(token: string): string {
|
||||
return createHash('sha256').update(token).digest('hex');
|
||||
}
|
||||
|
||||
private getInviteExpiryDate(): Date {
|
||||
const d = new Date();
|
||||
d.setDate(d.getDate() + 7);
|
||||
return d;
|
||||
}
|
||||
|
||||
private buildInviteUrl(token: string): string {
|
||||
const appUrl = process.env.FRONTEND_URL || 'http://localhost:3001';
|
||||
return `${appUrl}/accept-invite?token=${encodeURIComponent(token)}`;
|
||||
}
|
||||
|
||||
private async findValidInvitation(token: string) {
|
||||
const invitation = await this.prisma.staffInvitation.findUnique({
|
||||
where: { tokenHash: this.hashInviteToken(token) },
|
||||
include: {
|
||||
membership: {
|
||||
include: {
|
||||
user: { select: { id: true, email: true, name: true } },
|
||||
organization: { select: { id: true, name: true } },
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
if (!invitation) {
|
||||
throw new NotFoundException('Invitation not found');
|
||||
}
|
||||
if (invitation.revokedAt) {
|
||||
throw new BadRequestException('Invitation has been revoked');
|
||||
}
|
||||
if (invitation.expiresAt.getTime() <= Date.now()) {
|
||||
throw new BadRequestException('Invitation has expired');
|
||||
}
|
||||
return invitation;
|
||||
}
|
||||
|
||||
private canViewStaff(m: {
|
||||
isOwner: boolean;
|
||||
permissions: { permission: { name: string } }[];
|
||||
}): boolean {
|
||||
if (m.isOwner) return true;
|
||||
return m.permissions.some(
|
||||
(p) =>
|
||||
p.permission.name === 'TAB_STAFF_READ' || p.permission.name === 'TAB_STAFF_EDIT',
|
||||
);
|
||||
}
|
||||
|
||||
private canEditStaff(m: {
|
||||
isOwner: boolean;
|
||||
permissions: { permission: { name: string } }[];
|
||||
}): boolean {
|
||||
if (m.isOwner) return true;
|
||||
return m.permissions.some((p) => p.permission.name === 'TAB_STAFF_EDIT');
|
||||
}
|
||||
}
|
||||
@@ -9,11 +9,12 @@ const nextConfig = {
|
||||
// Disable x-powered-by header for security
|
||||
poweredByHeader: false,
|
||||
|
||||
// Configure image domains if needed
|
||||
// Configure allowed remote image sources
|
||||
images: {
|
||||
domains: process.env.NODE_ENV === 'production'
|
||||
? ['yourdomain.com']
|
||||
: ['localhost'],
|
||||
remotePatterns:
|
||||
process.env.NODE_ENV === 'production'
|
||||
? [{ protocol: 'https', hostname: 'yourdomain.com' }]
|
||||
: [{ protocol: 'http', hostname: 'localhost' }],
|
||||
},
|
||||
|
||||
// Environment variables that will be available at build time
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
'use client';
|
||||
import { useState } from 'react';
|
||||
import { Search, Filter, Plus } from 'lucide-react';
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { Input } from '@/components/ui/Input';
|
||||
import { Badge } from '@/components/ui/Badge';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { Badge } from '@/components/ui/common/Badge';
|
||||
// Mock data matching your design
|
||||
const invoices = [
|
||||
{ id: '#123456', patient: 'Ali Rahmani', date: '24/9/2026', service: 'Hygiene', amount: 300, paid: 0, status: 'unpaid' },
|
||||
|
||||
@@ -1,18 +1,21 @@
|
||||
'use client';
|
||||
|
||||
import { memo, useCallback, useEffect } from 'react';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import { memo, useEffect } from 'react';
|
||||
import { usePathname, useRouter } from 'next/navigation';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import Sidebar from '@/components/ui/Sidebar';
|
||||
import { ThemeToggle } from '@/components/ui/ThemeToggle';
|
||||
import { LogOut } from 'lucide-react';
|
||||
import Sidebar from '@/components/ui/common/Sidebar';
|
||||
import { ThemeToggle } from '@/components/ui/common/ThemeToggle';
|
||||
import { DashboardAccountMenu } from '@/components/ui/dashboard/DashboardAccountMenu';
|
||||
import {
|
||||
firstAccessibleDashboardPath,
|
||||
getRequiredReadPermissionForPath,
|
||||
hasPermission,
|
||||
} from '@/shared/permissions';
|
||||
|
||||
export default function DashboardLayout({ children }: { children: React.ReactNode }) {
|
||||
const { user, currentOrganization, isAuthReady, logout } = useAuth();
|
||||
const { user, currentOrganization, isAuthReady } = useAuth();
|
||||
const router = useRouter();
|
||||
const handleLogout = useCallback(() => {
|
||||
void logout();
|
||||
}, [logout]);
|
||||
const pathname = usePathname();
|
||||
|
||||
// ✅ AUTH GUARD (runs once per navigation group)
|
||||
useEffect(() => {
|
||||
@@ -27,7 +30,12 @@ export default function DashboardLayout({ children }: { children: React.ReactNod
|
||||
router.replace('/select-organization');
|
||||
return;
|
||||
}
|
||||
}, [isAuthReady, user, currentOrganization, router]);
|
||||
|
||||
const required = getRequiredReadPermissionForPath(pathname);
|
||||
if (required && !hasPermission(currentOrganization, required)) {
|
||||
router.replace(firstAccessibleDashboardPath(currentOrganization));
|
||||
}
|
||||
}, [isAuthReady, user, currentOrganization, router, pathname]);
|
||||
|
||||
// ✅ LOADING ONLY FOR INITIAL LOAD
|
||||
if (!isAuthReady) {
|
||||
@@ -51,11 +59,7 @@ export default function DashboardLayout({ children }: { children: React.ReactNod
|
||||
<Sidebar />
|
||||
|
||||
<div className="flex-1 flex flex-col">
|
||||
<DashboardHeader
|
||||
organizationName={currentOrganization.name}
|
||||
userName={user.name}
|
||||
onLogout={handleLogout}
|
||||
/>
|
||||
<DashboardHeader organizationName={currentOrganization.name} />
|
||||
|
||||
<main className="p-6 flex-1 overflow-y-auto">
|
||||
<div className="surface-panel p-6 min-h-full">
|
||||
@@ -69,27 +73,16 @@ export default function DashboardLayout({ children }: { children: React.ReactNod
|
||||
|
||||
const DashboardHeader = memo(function DashboardHeader({
|
||||
organizationName,
|
||||
userName,
|
||||
onLogout,
|
||||
}: {
|
||||
organizationName: string;
|
||||
userName: string;
|
||||
onLogout: () => void;
|
||||
}) {
|
||||
return (
|
||||
<header className="flex justify-between px-6 py-4 border-b border-border/70 backdrop-blur-sm">
|
||||
<h2 className="text-lg font-medium">{organizationName}</h2>
|
||||
<header className="relative z-40 h-[71px] flex justify-between items-center gap-4 px-6 border-b border-border/70 backdrop-blur-sm">
|
||||
<h2 className="text-lg font-medium truncate min-w-0">{organizationName}</h2>
|
||||
|
||||
<div className="flex items-center gap-4">
|
||||
<div className="flex items-center gap-3 shrink-0">
|
||||
<ThemeToggle />
|
||||
<span className="text-sm text-text-secondary">{userName}</span>
|
||||
<button
|
||||
onClick={onLogout}
|
||||
className="inline-flex items-center gap-2 text-sm text-text-secondary hover:text-text-primary transition-colors"
|
||||
>
|
||||
<LogOut className="w-4 h-4 icon-flat" />
|
||||
Logout
|
||||
</button>
|
||||
<DashboardAccountMenu />
|
||||
</div>
|
||||
</header>
|
||||
);
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
import { useEffect, useMemo, useState } from 'react';
|
||||
import { Plus } from 'lucide-react';
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { patientsApi } from '@/lib/api/patients';
|
||||
import {
|
||||
CreatePatientInput,
|
||||
@@ -10,10 +10,10 @@ import {
|
||||
Patient,
|
||||
TreatmentHistoryItem,
|
||||
} from '@/types/patient';
|
||||
import { PatientSearchSelect } from '@/components/patients/PatientSearchSelect';
|
||||
import { CreatePatientModal } from '@/components/patients/CreatePatientModal';
|
||||
import { PatientSummaryCard } from '@/components/patients/PatientSummaryCard';
|
||||
import { TreatmentHistoryPreview } from '@/components/patients/TreatmentHistoryPreview';
|
||||
import { PatientSearchSelect } from '../../../components/ui/patient/PatientSearchSelect';
|
||||
import { CreatePatientModal } from '../../../components/ui/patient/CreatePatientModal';
|
||||
import { PatientSummaryCard } from '../../../components/ui/patient/PatientSummaryCard';
|
||||
import { TreatmentHistoryPreview } from '../../../components/ui/patient/TreatmentHistoryPreview';
|
||||
|
||||
const EMPTY_PATIENT_FORM: CreatePatientInput = {
|
||||
firstName: '',
|
||||
@@ -201,7 +201,7 @@ export default function PatientsPage() {
|
||||
</div>
|
||||
|
||||
{(errorMessage || successMessage) && (
|
||||
<div className="absolute bottom-0 left-0 right-0 z-50 w-full">
|
||||
<div className="absolute bottom-0 left-0 right-0 z-10 w-full">
|
||||
{errorMessage && (
|
||||
<div className="rounded-[var(--radius-sm)] border border-red-500/50 bg-red-500/10 px-3 py-2 text-sm text-red-300 shadow-lg">
|
||||
{errorMessage}
|
||||
|
||||
29
frontend/src/app/(dashboard)/settings/account/page.tsx
Normal file
29
frontend/src/app/(dashboard)/settings/account/page.tsx
Normal file
@@ -0,0 +1,29 @@
|
||||
'use client';
|
||||
|
||||
import Link from 'next/link';
|
||||
|
||||
export default function AccountSettingsPage() {
|
||||
return (
|
||||
<div className="max-w-xl space-y-6">
|
||||
<div>
|
||||
<Link
|
||||
href="/today"
|
||||
className="text-sm text-primary hover:opacity-90"
|
||||
>
|
||||
← Back to app
|
||||
</Link>
|
||||
<h1 className="text-2xl font-semibold text-text-primary mt-4">Account</h1>
|
||||
<p className="text-text-secondary text-sm mt-2">
|
||||
Profile and security settings for your login.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="surface-card p-6 space-y-3">
|
||||
<p className="text-sm text-text-secondary">
|
||||
Password change and profile editing will be wired here next (e.g. invite
|
||||
flow, reset password).
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
20
frontend/src/app/(dashboard)/settings/organizations/page.tsx
Normal file
20
frontend/src/app/(dashboard)/settings/organizations/page.tsx
Normal file
@@ -0,0 +1,20 @@
|
||||
'use client';
|
||||
|
||||
import Link from 'next/link';
|
||||
import { OrganizationSelectorContent } from '@/components/ui/organization/OrganizationSelectorContent';
|
||||
|
||||
export default function DashboardOrganizationsSettingsPage() {
|
||||
return (
|
||||
<div className="max-w-3xl space-y-6">
|
||||
<div>
|
||||
<Link
|
||||
href="/today"
|
||||
className="text-sm text-primary hover:opacity-90"
|
||||
>
|
||||
← Back to app
|
||||
</Link>
|
||||
</div>
|
||||
<OrganizationSelectorContent />
|
||||
</div>
|
||||
);
|
||||
}
|
||||
135
frontend/src/app/(dashboard)/settings/subscriptions/page.tsx
Normal file
135
frontend/src/app/(dashboard)/settings/subscriptions/page.tsx
Normal file
@@ -0,0 +1,135 @@
|
||||
'use client';
|
||||
|
||||
import { useEffect, useState } from 'react';
|
||||
import Link from 'next/link';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { authApi } from '@/lib/api/auth';
|
||||
import type { SubscriptionAlertData } from '@/types/subscription';
|
||||
|
||||
export default function SubscriptionsSettingsPage() {
|
||||
const { currentOrganization } = useAuth();
|
||||
const router = useRouter();
|
||||
const [alert, setAlert] = useState<SubscriptionAlertData | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
if (currentOrganization && !currentOrganization.isOwner) {
|
||||
router.replace('/today');
|
||||
}
|
||||
}, [currentOrganization, router]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!currentOrganization?.isOwner) return;
|
||||
void authApi.getSubscriptionAlert().then((r) => {
|
||||
if (r.success) setAlert(r.data);
|
||||
});
|
||||
}, [currentOrganization?.id, currentOrganization?.isOwner]);
|
||||
|
||||
if (!currentOrganization) {
|
||||
return (
|
||||
<p className="text-text-secondary text-sm">Loading...</p>
|
||||
);
|
||||
}
|
||||
|
||||
if (!currentOrganization.isOwner) {
|
||||
return (
|
||||
<p className="text-text-secondary text-sm">Redirecting...</p>
|
||||
);
|
||||
}
|
||||
|
||||
const plan = currentOrganization.plan;
|
||||
const maxUsers = plan?.maxUsers;
|
||||
const isUnlimited = typeof maxUsers === 'number' && maxUsers >= 999999;
|
||||
const seatsUsed = alert?.seatsUsed;
|
||||
const seatsRemaining =
|
||||
typeof seatsUsed === 'number' && typeof maxUsers === 'number' && !isUnlimited
|
||||
? Math.max(0, maxUsers - seatsUsed)
|
||||
: null;
|
||||
const daysUntilPlanEnd = alert?.daysUntilPlanEnd ?? null;
|
||||
const planDayTone =
|
||||
daysUntilPlanEnd == null
|
||||
? 'text-text-primary'
|
||||
: daysUntilPlanEnd > 20
|
||||
? 'text-emerald-400'
|
||||
: daysUntilPlanEnd >= 10
|
||||
? 'text-amber-300'
|
||||
: 'text-red-400';
|
||||
|
||||
return (
|
||||
<div className="max-w-4xl space-y-6">
|
||||
<div>
|
||||
<Link
|
||||
href="/today"
|
||||
className="text-sm text-primary hover:opacity-90"
|
||||
>
|
||||
← Back to app
|
||||
</Link>
|
||||
<h1 className="text-2xl font-semibold text-text-primary mt-4">Subscriptions</h1>
|
||||
<p className="text-text-secondary text-sm mt-2">
|
||||
Your DyoLink workspace plan and seats for{' '}
|
||||
<span className="text-text-primary font-medium">{currentOrganization.name}</span>.
|
||||
Clinic and lab income tracking stays under the sidebar{' '}
|
||||
<span className="text-text-primary">Billing</span> tab.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="surface-card p-6 space-y-4">
|
||||
<div className="grid gap-4 sm:grid-cols-2 lg:grid-cols-5">
|
||||
<div>
|
||||
<p className="text-xs text-text-muted uppercase tracking-wide">Current plan</p>
|
||||
<p className="text-lg font-medium text-text-primary capitalize">
|
||||
{plan?.name ?? '—'}
|
||||
</p>
|
||||
</div>
|
||||
<div>
|
||||
<p className="text-xs text-text-muted uppercase tracking-wide">Plan price</p>
|
||||
<p className="text-lg font-medium text-text-primary">
|
||||
{typeof plan?.price === 'number' ? `$${plan.price}` : '—'}
|
||||
</p>
|
||||
</div>
|
||||
<div>
|
||||
<p className="text-xs text-text-muted uppercase tracking-wide">Seats used</p>
|
||||
<p className="text-lg font-medium text-text-primary">
|
||||
{typeof seatsUsed === 'number' ? seatsUsed : '—'}
|
||||
{typeof maxUsers === 'number' ? ` / ${isUnlimited ? 'Unlimited' : maxUsers}` : ''}
|
||||
</p>
|
||||
</div>
|
||||
<div>
|
||||
<p className="text-xs text-text-muted uppercase tracking-wide">Seats remaining</p>
|
||||
<p className="text-lg font-medium text-text-primary">
|
||||
{isUnlimited ? 'Unlimited' : seatsRemaining ?? '—'}
|
||||
</p>
|
||||
</div>
|
||||
<div>
|
||||
<p className="text-xs text-text-muted uppercase tracking-wide">Days remaining</p>
|
||||
<p className={`text-lg font-medium ${planDayTone}`}>
|
||||
{daysUntilPlanEnd ?? '—'}
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{alert?.showWarning && (
|
||||
<div className="text-sm text-text-secondary space-y-1">
|
||||
{alert.trialExpired && (
|
||||
<p>Trial period has ended. Choose a plan when checkout is available.</p>
|
||||
)}
|
||||
{!alert.trialExpired && alert.trialEndingSoon && (
|
||||
<p>
|
||||
Trial ends in {alert.daysUntilTrialEnd ?? '—'} day(s).
|
||||
</p>
|
||||
)}
|
||||
{!alert.trialExpired && !alert.trialEndingSoon && alert.seatsLow && (
|
||||
<p>Seat usage is high for this organization.</p>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
|
||||
<p className="text-sm text-text-secondary">
|
||||
Payment and plan upgrades will connect here. The warning on the settings
|
||||
icon is only shown to workspace owners when seats are low or the trial window
|
||||
is ending.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
/** Feature groups for staff invite/edit UI — matches backend seed */
|
||||
export const STAFF_FEATURE_GROUPS = [
|
||||
{ label: 'Today', read: 'TAB_TODAY_READ', edit: 'TAB_TODAY_EDIT' },
|
||||
{ label: 'Patients', read: 'TAB_PATIENTS_READ', edit: 'TAB_PATIENTS_EDIT' },
|
||||
{ label: 'Appointments', read: 'TAB_APPOINTMENTS_READ', edit: 'TAB_APPOINTMENTS_EDIT' },
|
||||
{ label: 'Staff Management', read: 'TAB_STAFF_READ', edit: 'TAB_STAFF_EDIT' },
|
||||
{ label: 'Lab Management', read: 'TAB_LAB_READ', edit: 'TAB_LAB_EDIT' },
|
||||
{ label: 'Billing', read: 'TAB_BILLING_READ', edit: 'TAB_BILLING_EDIT' },
|
||||
{ label: 'Reports', read: 'TAB_REPORTS_READ', edit: 'TAB_REPORTS_EDIT' },
|
||||
] as const;
|
||||
|
||||
/** Map EDIT key -> { read, edit } for checkbox grid */
|
||||
export type FeaturePermState = Record<string, { read: boolean; edit: boolean }>;
|
||||
|
||||
export function emptyFeaturePermissionState(): FeaturePermState {
|
||||
const s: FeaturePermState = {};
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
s[g.edit] = { read: false, edit: false };
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
export function featureStateFromPermissionNames(names: string[]): FeaturePermState {
|
||||
const set = new Set(names);
|
||||
const s = emptyFeaturePermissionState();
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
const hasEdit = set.has(g.edit);
|
||||
const hasRead = set.has(g.read) || hasEdit;
|
||||
s[g.edit] = { read: hasRead, edit: hasEdit };
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
export function permissionNamesFromFeatureState(state: FeaturePermState): string[] {
|
||||
const out: string[] = [];
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
const cell = state[g.edit];
|
||||
if (!cell) continue;
|
||||
if (cell.edit) out.push(g.edit);
|
||||
else if (cell.read) out.push(g.read);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
@@ -1,10 +1,501 @@
|
||||
export default function StaffPage() {
|
||||
'use client';
|
||||
|
||||
import { useCallback, useEffect, useMemo, useState } from 'react';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import {
|
||||
firstAccessibleDashboardPath,
|
||||
canEditStaff,
|
||||
canViewStaff,
|
||||
} from '@/shared/permissions';
|
||||
import {
|
||||
STAFF_FEATURE_GROUPS,
|
||||
permissionNamesFromFeatureState,
|
||||
emptyFeaturePermissionState,
|
||||
featureStateFromPermissionNames,
|
||||
formatAccessSummary,
|
||||
type FeaturePermState,
|
||||
} from './staff-permission-form';
|
||||
import { UserPlus, Pencil, Trash2, Copy, Check, X, Clock3 } from 'lucide-react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { staffApi, type StaffMemberDto } from '@/lib/api/staff';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { Checkbox } from '@/components/ui/common/Checkbox';
|
||||
import type { ApiError } from '@/types/api';
|
||||
|
||||
function formatApiMessage(err: unknown): string {
|
||||
if (!err || typeof err !== 'object') return 'Something went wrong';
|
||||
const m = (err as ApiError).message;
|
||||
if (Array.isArray(m)) return m.join(', ');
|
||||
if (typeof m === 'string') return m;
|
||||
return 'Something went wrong';
|
||||
}
|
||||
|
||||
function PermissionGrid({
|
||||
state,
|
||||
onChange,
|
||||
disabled,
|
||||
}: {
|
||||
state: FeaturePermState;
|
||||
onChange: (next: FeaturePermState) => void;
|
||||
disabled?: boolean;
|
||||
}) {
|
||||
const setRead = (editKey: string, read: boolean) => {
|
||||
const cur = state[editKey] ?? { read: false, edit: false };
|
||||
onChange({
|
||||
...state,
|
||||
[editKey]: { read, edit: read ? cur.edit : false },
|
||||
});
|
||||
};
|
||||
|
||||
const setEdit = (editKey: string, edit: boolean) => {
|
||||
const cur = state[editKey] ?? { read: false, edit: false };
|
||||
onChange({
|
||||
...state,
|
||||
[editKey]: { read: edit || cur.read, edit },
|
||||
});
|
||||
};
|
||||
|
||||
return (
|
||||
<div className="space-y-3">
|
||||
<h1 className="text-2xl font-semibold text-text-primary">Staff Management</h1>
|
||||
<p className="text-sm text-text-secondary">
|
||||
Staff management module is coming soon.
|
||||
</p>
|
||||
<div className="grid gap-3 sm:grid-cols-2">
|
||||
{STAFF_FEATURE_GROUPS.map((g) => {
|
||||
const cell = state[g.edit] ?? { read: false, edit: false };
|
||||
return (
|
||||
<div
|
||||
key={g.edit}
|
||||
className="flex flex-col gap-3 rounded-[var(--radius-md)] border border-border/60 bg-background-card/50 px-3 py-3"
|
||||
>
|
||||
<span className="text-sm font-medium text-text-primary">{g.label}</span>
|
||||
<div className="flex flex-col gap-2.5 pl-0.5">
|
||||
<Checkbox
|
||||
checked={cell.read}
|
||||
disabled={disabled}
|
||||
label="View"
|
||||
onChange={(v) => setRead(g.edit, v)}
|
||||
/>
|
||||
<Checkbox
|
||||
checked={cell.edit}
|
||||
disabled={disabled}
|
||||
label="Edit"
|
||||
onChange={(v) => setEdit(g.edit, v)}
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
})}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
export default function StaffPage() {
|
||||
const router = useRouter();
|
||||
const { currentOrganization, user } = useAuth();
|
||||
const [members, setMembers] = useState<StaffMemberDto[]>([]);
|
||||
const [seats, setSeats] = useState<{
|
||||
used: number;
|
||||
limit: number | null;
|
||||
unlimited: boolean;
|
||||
} | null>(null);
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState('');
|
||||
const [success, setSuccess] = useState('');
|
||||
|
||||
const [inviteOpen, setInviteOpen] = useState(false);
|
||||
const [inviteEmail, setInviteEmail] = useState('');
|
||||
const [inviteName, setInviteName] = useState('');
|
||||
const [invitePerms, setInvitePerms] = useState(() => emptyFeaturePermissionState());
|
||||
const [inviteLoading, setInviteLoading] = useState(false);
|
||||
const [copiedInviteLink, setCopiedInviteLink] = useState(false);
|
||||
const [lastInviteInfo, setLastInviteInfo] = useState<{
|
||||
name: string;
|
||||
email: string;
|
||||
invitationUrl: string | null;
|
||||
invitationStatus: 'PENDING' | 'ACCEPTED';
|
||||
} | null>(null);
|
||||
|
||||
const [editing, setEditing] = useState<StaffMemberDto | null>(null);
|
||||
const [editName, setEditName] = useState('');
|
||||
const [editPerms, setEditPerms] = useState(() => emptyFeaturePermissionState());
|
||||
const [editLoading, setEditLoading] = useState(false);
|
||||
|
||||
const canEdit = useMemo(() => canEditStaff(currentOrganization), [currentOrganization]);
|
||||
const atSeatLimit = useMemo(() => {
|
||||
if (!seats || seats.unlimited) return false;
|
||||
if (seats.limit == null) return false;
|
||||
return seats.used >= seats.limit;
|
||||
}, [seats]);
|
||||
|
||||
const load = useCallback(async () => {
|
||||
setError('');
|
||||
setLoading(true);
|
||||
try {
|
||||
const res = await staffApi.list();
|
||||
setMembers(res.data.members);
|
||||
setSeats(res.data.seats);
|
||||
} catch (e) {
|
||||
setError(formatApiMessage(e));
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
void load();
|
||||
}, [load]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!currentOrganization) return;
|
||||
if (!canViewStaff(currentOrganization)) {
|
||||
router.replace(firstAccessibleDashboardPath(currentOrganization));
|
||||
}
|
||||
}, [currentOrganization, router]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!success) return;
|
||||
const t = setTimeout(() => setSuccess(''), 4000);
|
||||
return () => clearTimeout(t);
|
||||
}, [success]);
|
||||
|
||||
async function submitInvite() {
|
||||
setInviteLoading(true);
|
||||
setError('');
|
||||
setLastInviteInfo(null);
|
||||
const displayName = inviteName.trim();
|
||||
const displayEmail = inviteEmail.trim();
|
||||
try {
|
||||
const permissionNames = permissionNamesFromFeatureState(invitePerms);
|
||||
const res = await staffApi.invite({
|
||||
email: displayEmail,
|
||||
name: displayName,
|
||||
permissionNames,
|
||||
});
|
||||
setLastInviteInfo({
|
||||
name: displayName,
|
||||
email: res.data.email,
|
||||
invitationUrl: res.data.invitationUrl,
|
||||
invitationStatus: res.data.invitationStatus,
|
||||
});
|
||||
setSuccess('');
|
||||
setInviteOpen(false);
|
||||
setInviteEmail('');
|
||||
setInviteName('');
|
||||
setInvitePerms(emptyFeaturePermissionState());
|
||||
await load();
|
||||
} catch (e) {
|
||||
setError(formatApiMessage(e));
|
||||
} finally {
|
||||
setInviteLoading(false);
|
||||
}
|
||||
}
|
||||
|
||||
function openEdit(m: StaffMemberDto) {
|
||||
if (m.isOwner) return;
|
||||
setEditing(m);
|
||||
setEditName(m.name);
|
||||
setEditPerms(
|
||||
featureStateFromPermissionNames(m.permissions ?? []),
|
||||
);
|
||||
}
|
||||
|
||||
async function submitEdit() {
|
||||
if (!editing) return;
|
||||
setEditLoading(true);
|
||||
setError('');
|
||||
try {
|
||||
await staffApi.updateMember(editing.id, {
|
||||
name: editName.trim(),
|
||||
permissionNames: permissionNamesFromFeatureState(editPerms),
|
||||
});
|
||||
setSuccess('Member updated');
|
||||
setEditing(null);
|
||||
await load();
|
||||
} catch (e) {
|
||||
setError(formatApiMessage(e));
|
||||
} finally {
|
||||
setEditLoading(false);
|
||||
}
|
||||
}
|
||||
|
||||
async function removeMember(m: StaffMemberDto) {
|
||||
if (m.isOwner) return;
|
||||
if (m.userId === user?.id) {
|
||||
if (!confirm('Remove yourself from this organization? You will lose access.')) return;
|
||||
} else {
|
||||
if (!confirm(`Remove ${m.name} from this organization?`)) return;
|
||||
}
|
||||
setError('');
|
||||
try {
|
||||
await staffApi.removeMember(m.id);
|
||||
setSuccess('Member removed');
|
||||
await load();
|
||||
} catch (e) {
|
||||
setError(formatApiMessage(e));
|
||||
}
|
||||
}
|
||||
|
||||
if (!currentOrganization || !canViewStaff(currentOrganization)) {
|
||||
return (
|
||||
<p className="text-sm text-text-secondary">Redirecting…</p>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="space-y-6 max-w-5xl">
|
||||
<div className="flex flex-col gap-3 sm:flex-row sm:items-start sm:justify-between">
|
||||
<div>
|
||||
<h1 className="text-2xl font-semibold text-text-primary">Staff Management</h1>
|
||||
<p className="text-sm text-text-secondary mt-1">
|
||||
Invite teammates, set tab access, and stay within your plan seat limit.
|
||||
</p>
|
||||
</div>
|
||||
{canEdit && (
|
||||
<Button
|
||||
size="sm"
|
||||
onClick={() => {
|
||||
setInviteOpen(true);
|
||||
setLastInviteInfo(null);
|
||||
}}
|
||||
disabled={atSeatLimit}
|
||||
className="shrink-0"
|
||||
>
|
||||
<UserPlus className="w-4 h-4 mr-2" />
|
||||
Invite member
|
||||
</Button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{seats && (
|
||||
<p className="text-sm text-text-secondary">
|
||||
Seats:{' '}
|
||||
<span className="text-text-primary font-medium">
|
||||
{seats.used}
|
||||
{seats.unlimited ? ' (unlimited plan)' : ` / ${seats.limit}`}
|
||||
</span>
|
||||
{!seats.unlimited && atSeatLimit && (
|
||||
<span className="text-amber-600 dark:text-amber-400 ml-2">
|
||||
Limit reached — remove a member or upgrade your plan.
|
||||
</span>
|
||||
)}
|
||||
</p>
|
||||
)}
|
||||
|
||||
{error && (
|
||||
<div className="rounded-[var(--radius-md)] border border-red-500/40 bg-red-500/10 px-4 py-3 text-sm text-red-700 dark:text-red-300">
|
||||
{error}
|
||||
</div>
|
||||
)}
|
||||
|
||||
{success && (
|
||||
<div className="rounded-[var(--radius-md)] border border-primary/30 bg-primary-soft/40 px-4 py-3 text-sm text-text-primary">
|
||||
{success}
|
||||
</div>
|
||||
)}
|
||||
|
||||
{lastInviteInfo && (
|
||||
<div className="relative rounded-[var(--radius-md)] border border-border-strong bg-background-secondary/90 px-4 py-3 pr-12 shadow-[inset_0_1px_0_rgba(255,255,255,0.04)] space-y-3">
|
||||
<button
|
||||
type="button"
|
||||
className="absolute right-2 top-2 p-1.5 rounded-[var(--radius-sm)] text-text-muted hover:text-text-primary hover:bg-background-card/80"
|
||||
aria-label="Dismiss"
|
||||
onClick={() => {
|
||||
setLastInviteInfo(null);
|
||||
}}
|
||||
>
|
||||
<X className="w-4 h-4" />
|
||||
</button>
|
||||
<p className="text-sm text-text-primary pr-6">
|
||||
<span className="font-medium">{lastInviteInfo.name}</span> ({lastInviteInfo.email}) was invited.
|
||||
{lastInviteInfo.invitationStatus === 'PENDING'
|
||||
? ' Invitation is pending until they open the link, set a password, and log in.'
|
||||
: ' Invitation was accepted immediately.'}
|
||||
</p>
|
||||
{lastInviteInfo.invitationUrl && (
|
||||
<div className="space-y-2 pt-1 border-t border-border/60">
|
||||
<p className="text-xs font-medium text-text-secondary uppercase tracking-wide">
|
||||
Invite link
|
||||
</p>
|
||||
<div className="flex flex-wrap items-center gap-2">
|
||||
<code className="text-sm px-2 py-1.5 rounded-[var(--radius-sm)] bg-background-card border border-border font-mono break-all">
|
||||
{lastInviteInfo.invitationUrl}
|
||||
</code>
|
||||
<Button
|
||||
type="button"
|
||||
variant="outline"
|
||||
size="sm"
|
||||
onClick={async () => {
|
||||
try {
|
||||
await navigator.clipboard.writeText(lastInviteInfo.invitationUrl as string);
|
||||
setCopiedInviteLink(true);
|
||||
setTimeout(() => setCopiedInviteLink(false), 1500);
|
||||
} catch {
|
||||
setError('Could not copy invitation link');
|
||||
}
|
||||
}}
|
||||
>
|
||||
{copiedInviteLink ? <Check className="w-4 h-4" /> : <Copy className="w-4 h-4" />}
|
||||
<span className="ml-1">{copiedInviteLink ? 'Copied' : 'Copy link'}</span>
|
||||
</Button>
|
||||
</div>
|
||||
<p className="text-xs text-text-muted">
|
||||
Share this link manually via SMS or email. They must set password first.
|
||||
</p>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
|
||||
{loading ? (
|
||||
<p className="text-sm text-text-secondary">Loading team…</p>
|
||||
) : (
|
||||
<div className="overflow-x-auto rounded-[var(--radius-md)] border border-border/70">
|
||||
<table className="w-full text-sm">
|
||||
<thead>
|
||||
<tr className="border-b border-border/70 text-left text-text-secondary">
|
||||
<th className="p-3 font-medium">Name</th>
|
||||
<th className="p-3 font-medium">Email</th>
|
||||
<th className="p-3 font-medium">Role</th>
|
||||
<th className="p-3 font-medium">Status</th>
|
||||
<th className="p-3 font-medium">Access</th>
|
||||
{canEdit && <th className="p-3 font-medium w-28">Actions</th>}
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{members.map((m) => (
|
||||
<tr key={m.id} className="border-b border-border/40 last:border-0">
|
||||
<td className="p-3 text-text-primary">{m.name}</td>
|
||||
<td className="p-3 text-text-secondary">{m.email}</td>
|
||||
<td className="p-3">
|
||||
{m.isOwner ? (
|
||||
<span className="text-primary font-medium">Owner</span>
|
||||
) : (
|
||||
<span className="text-text-secondary">Staff</span>
|
||||
)}
|
||||
</td>
|
||||
<td className="p-3">
|
||||
{m.isOwner || m.invitationStatus === 'ACTIVE' ? (
|
||||
<span className="inline-flex items-center rounded-full border border-emerald-600/40 bg-emerald-600/15 px-2 py-0.5 text-xs text-emerald-400">
|
||||
Active
|
||||
</span>
|
||||
) : m.invitationStatus === 'PENDING' ? (
|
||||
<span className="inline-flex items-center gap-1 rounded-full border border-amber-500/40 bg-amber-500/15 px-2 py-0.5 text-xs text-amber-300">
|
||||
<Clock3 className="h-3 w-3" />
|
||||
Pending
|
||||
</span>
|
||||
) : (
|
||||
<span className="inline-flex items-center rounded-full border border-red-500/40 bg-red-500/15 px-2 py-0.5 text-xs text-red-300">
|
||||
Expired
|
||||
</span>
|
||||
)}
|
||||
</td>
|
||||
<td className="p-3 text-text-secondary max-w-md">
|
||||
{m.isOwner ? (
|
||||
<span className="text-text-muted">All features</span>
|
||||
) : (
|
||||
<span className="line-clamp-3 text-sm leading-relaxed">
|
||||
{formatAccessSummary(m.permissions)}
|
||||
</span>
|
||||
)}
|
||||
</td>
|
||||
{canEdit && (
|
||||
<td className="p-3">
|
||||
{!m.isOwner && (
|
||||
<div className="flex items-center gap-1">
|
||||
<button
|
||||
type="button"
|
||||
className="p-2 rounded-md text-text-secondary hover:bg-background-card/80 hover:text-text-primary"
|
||||
aria-label="Edit member"
|
||||
onClick={() => openEdit(m)}
|
||||
>
|
||||
<Pencil className="w-4 h-4" />
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
className="p-2 rounded-md text-text-secondary hover:bg-red-500/15 hover:text-red-600"
|
||||
aria-label="Remove member"
|
||||
onClick={() => void removeMember(m)}
|
||||
>
|
||||
<Trash2 className="w-4 h-4" />
|
||||
</button>
|
||||
</div>
|
||||
)}
|
||||
</td>
|
||||
)}
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{inviteOpen && (
|
||||
<div className="fixed inset-0 z-50 flex items-center justify-center p-4 bg-black/50">
|
||||
<div
|
||||
className="w-full max-w-lg max-h-[90vh] overflow-y-auto rounded-[var(--radius-md)] border border-border bg-background-secondary p-6 shadow-xl space-y-4"
|
||||
role="dialog"
|
||||
aria-modal="true"
|
||||
aria-labelledby="invite-staff-title"
|
||||
>
|
||||
<h2 id="invite-staff-title" className="text-lg font-semibold text-text-primary">
|
||||
Invite team member
|
||||
</h2>
|
||||
<Input
|
||||
label="Email"
|
||||
type="email"
|
||||
value={inviteEmail}
|
||||
onChange={(e) => setInviteEmail(e.target.value)}
|
||||
autoComplete="off"
|
||||
/>
|
||||
<Input
|
||||
label="Display name"
|
||||
value={inviteName}
|
||||
onChange={(e) => setInviteName(e.target.value)}
|
||||
/>
|
||||
<div>
|
||||
<p className="text-sm font-medium text-text-secondary mb-2">Tab access</p>
|
||||
<PermissionGrid state={invitePerms} onChange={setInvitePerms} />
|
||||
</div>
|
||||
<div className="flex justify-end gap-2 pt-2">
|
||||
<Button variant="outline" type="button" onClick={() => setInviteOpen(false)}>
|
||||
Cancel
|
||||
</Button>
|
||||
<Button
|
||||
type="button"
|
||||
isLoading={inviteLoading}
|
||||
disabled={!inviteEmail.trim() || !inviteName.trim()}
|
||||
onClick={() => void submitInvite()}
|
||||
>
|
||||
Send invite
|
||||
</Button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{editing && (
|
||||
<div className="fixed inset-0 z-50 flex items-center justify-center p-4 bg-black/50">
|
||||
<div
|
||||
className="w-full max-w-lg max-h-[90vh] overflow-y-auto rounded-[var(--radius-md)] border border-border bg-background-secondary p-6 shadow-xl space-y-4"
|
||||
role="dialog"
|
||||
aria-modal="true"
|
||||
>
|
||||
<h2 className="text-lg font-semibold text-text-primary">Edit member</h2>
|
||||
<p className="text-xs text-text-muted">{editing.email}</p>
|
||||
<Input label="Display name" value={editName} onChange={(e) => setEditName(e.target.value)} />
|
||||
<div>
|
||||
<p className="text-sm font-medium text-text-secondary mb-2">Tab access</p>
|
||||
<PermissionGrid state={editPerms} onChange={setEditPerms} />
|
||||
</div>
|
||||
<div className="flex justify-end gap-2 pt-2">
|
||||
<Button variant="outline" type="button" onClick={() => setEditing(null)}>
|
||||
Cancel
|
||||
</Button>
|
||||
<Button type="button" isLoading={editLoading} onClick={() => void submitEdit()}>
|
||||
Save
|
||||
</Button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
60
frontend/src/app/(dashboard)/staff/staff-permission-form.ts
Normal file
60
frontend/src/app/(dashboard)/staff/staff-permission-form.ts
Normal file
@@ -0,0 +1,60 @@
|
||||
/**
|
||||
* Staff route only: tab matrix + checkbox state ↔ TAB_* permission names.
|
||||
* Add presentational pieces under ./components/ as the UI grows.
|
||||
*/
|
||||
|
||||
export const STAFF_FEATURE_GROUPS = [
|
||||
{ label: 'Today', read: 'TAB_TODAY_READ', edit: 'TAB_TODAY_EDIT' },
|
||||
{ label: 'Patients', read: 'TAB_PATIENTS_READ', edit: 'TAB_PATIENTS_EDIT' },
|
||||
{ label: 'Appointments', read: 'TAB_APPOINTMENTS_READ', edit: 'TAB_APPOINTMENTS_EDIT' },
|
||||
{ label: 'Staff Management', read: 'TAB_STAFF_READ', edit: 'TAB_STAFF_EDIT' },
|
||||
{ label: 'Lab Management', read: 'TAB_LAB_READ', edit: 'TAB_LAB_EDIT' },
|
||||
{ label: 'Billing', read: 'TAB_BILLING_READ', edit: 'TAB_BILLING_EDIT' },
|
||||
{ label: 'Reports', read: 'TAB_REPORTS_READ', edit: 'TAB_REPORTS_EDIT' },
|
||||
] as const;
|
||||
|
||||
export type FeaturePermState = Record<string, { read: boolean; edit: boolean }>;
|
||||
|
||||
export function emptyFeaturePermissionState(): FeaturePermState {
|
||||
const s: FeaturePermState = {};
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
s[g.edit] = { read: false, edit: false };
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
export function featureStateFromPermissionNames(names: string[]): FeaturePermState {
|
||||
const set = new Set(names);
|
||||
const s = emptyFeaturePermissionState();
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
const hasEdit = set.has(g.edit);
|
||||
const hasRead = set.has(g.read) || hasEdit;
|
||||
s[g.edit] = { read: hasRead, edit: hasEdit };
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
export function permissionNamesFromFeatureState(state: FeaturePermState): string[] {
|
||||
const out: string[] = [];
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
const cell = state[g.edit];
|
||||
if (!cell) continue;
|
||||
if (cell.edit) out.push(g.edit);
|
||||
else if (cell.read) out.push(g.read);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** Human-readable access for the team table — feature name, or "Feature (Read only)" */
|
||||
export function formatAccessSummary(permissionNames: string[] | null | undefined): string {
|
||||
if (!permissionNames?.length) return 'No tab access';
|
||||
const set = new Set(permissionNames);
|
||||
const parts: string[] = [];
|
||||
for (const g of STAFF_FEATURE_GROUPS) {
|
||||
const hasEdit = set.has(g.edit);
|
||||
const hasRead = set.has(g.read) || hasEdit;
|
||||
if (!hasRead) continue;
|
||||
parts.push(hasEdit ? g.label : `${g.label} (Read only)`);
|
||||
}
|
||||
return parts.length ? parts.join(' · ') : 'No tab access';
|
||||
}
|
||||
166
frontend/src/app/(public)/accept-invite/page.tsx
Normal file
166
frontend/src/app/(public)/accept-invite/page.tsx
Normal file
@@ -0,0 +1,166 @@
|
||||
'use client';
|
||||
|
||||
import { useEffect, useMemo, useState } from 'react';
|
||||
import { Suspense } from 'react';
|
||||
import Link from 'next/link';
|
||||
import { useRouter, useSearchParams } from 'next/navigation';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { staffApi } from '@/lib/api/staff';
|
||||
|
||||
function AcceptInviteContent() {
|
||||
const params = useSearchParams();
|
||||
const router = useRouter();
|
||||
const token = useMemo(() => params.get('token') || '', [params]);
|
||||
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [submitting, setSubmitting] = useState(false);
|
||||
const [error, setError] = useState('');
|
||||
const [success, setSuccess] = useState('');
|
||||
const [inviteInfo, setInviteInfo] = useState<{
|
||||
email: string;
|
||||
name: string;
|
||||
organizationName: string;
|
||||
expiresAt: string;
|
||||
status: 'PENDING' | 'ACCEPTED';
|
||||
} | null>(null);
|
||||
|
||||
const [name, setName] = useState('');
|
||||
const [password, setPassword] = useState('');
|
||||
const [confirmPassword, setConfirmPassword] = useState('');
|
||||
|
||||
useEffect(() => {
|
||||
if (!token) {
|
||||
setLoading(false);
|
||||
setError('Invalid invitation link');
|
||||
return;
|
||||
}
|
||||
|
||||
void (async () => {
|
||||
setLoading(true);
|
||||
setError('');
|
||||
try {
|
||||
const res = await staffApi.previewInvite(token);
|
||||
setInviteInfo(res.data);
|
||||
setName(res.data.name || '');
|
||||
if (res.data.status === 'ACCEPTED') {
|
||||
setSuccess('This invitation is already accepted. You can log in now.');
|
||||
}
|
||||
} catch (e: any) {
|
||||
setError(e?.message || 'Could not load invitation');
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
})();
|
||||
}, [token]);
|
||||
|
||||
async function onAccept() {
|
||||
if (!token) return;
|
||||
setError('');
|
||||
setSuccess('');
|
||||
if (!name.trim()) {
|
||||
setError('Name is required');
|
||||
return;
|
||||
}
|
||||
if (password.length < 8) {
|
||||
setError('Password must be at least 8 characters');
|
||||
return;
|
||||
}
|
||||
if (password !== confirmPassword) {
|
||||
setError('Passwords do not match');
|
||||
return;
|
||||
}
|
||||
|
||||
setSubmitting(true);
|
||||
try {
|
||||
await staffApi.acceptInvite({
|
||||
token,
|
||||
name: name.trim(),
|
||||
password,
|
||||
});
|
||||
setSuccess('Invitation accepted. Redirecting to login...');
|
||||
setTimeout(() => {
|
||||
router.replace('/login');
|
||||
}, 1000);
|
||||
} catch (e: any) {
|
||||
setError(e?.message || 'Could not accept invitation');
|
||||
} finally {
|
||||
setSubmitting(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="min-h-screen app-web-bg flex items-center justify-center p-4">
|
||||
<div className="w-full max-w-md surface-card p-6 space-y-5">
|
||||
<h1 className="text-xl font-semibold text-text-primary">Accept invitation</h1>
|
||||
|
||||
{loading ? (
|
||||
<p className="text-sm text-text-secondary">Loading invitation...</p>
|
||||
) : (
|
||||
<>
|
||||
{inviteInfo && (
|
||||
<div className="rounded-[var(--radius-md)] border border-border/70 bg-background-secondary/70 px-3 py-2 text-sm text-text-secondary space-y-1">
|
||||
<p>
|
||||
Organization: <span className="text-text-primary">{inviteInfo.organizationName}</span>
|
||||
</p>
|
||||
<p>
|
||||
Email: <span className="text-text-primary">{inviteInfo.email}</span>
|
||||
</p>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{error && (
|
||||
<div className="rounded-[var(--radius-md)] border border-red-500/40 bg-red-500/10 px-3 py-2 text-sm text-red-300">
|
||||
{error}
|
||||
</div>
|
||||
)}
|
||||
{success && (
|
||||
<div className="rounded-[var(--radius-md)] border border-primary/30 bg-primary-soft/40 px-3 py-2 text-sm text-text-primary">
|
||||
{success}
|
||||
</div>
|
||||
)}
|
||||
|
||||
{inviteInfo?.status !== 'ACCEPTED' && (
|
||||
<div className="space-y-3">
|
||||
<Input label="Name" value={name} onChange={(e) => setName(e.target.value)} />
|
||||
<Input
|
||||
label="Create password"
|
||||
type="password"
|
||||
value={password}
|
||||
onChange={(e) => setPassword(e.target.value)}
|
||||
/>
|
||||
<Input
|
||||
label="Confirm password"
|
||||
type="password"
|
||||
value={confirmPassword}
|
||||
onChange={(e) => setConfirmPassword(e.target.value)}
|
||||
/>
|
||||
<Button type="button" fullWidth isLoading={submitting} onClick={() => void onAccept()}>
|
||||
Activate account
|
||||
</Button>
|
||||
</div>
|
||||
)}
|
||||
|
||||
<p className="text-xs text-text-muted">
|
||||
Already have access? <Link href="/login" className="text-primary">Go to login</Link>
|
||||
</p>
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
export default function AcceptInvitePage() {
|
||||
return (
|
||||
<Suspense
|
||||
fallback={
|
||||
<div className="min-h-screen app-web-bg flex items-center justify-center">
|
||||
<p className="text-sm text-text-secondary">Loading invitation...</p>
|
||||
</div>
|
||||
}
|
||||
>
|
||||
<AcceptInviteContent />
|
||||
</Suspense>
|
||||
);
|
||||
}
|
||||
@@ -116,8 +116,8 @@ import Link from 'next/link';
|
||||
import { Mail, Lock } from 'lucide-react';
|
||||
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { Input } from '@/components/ui/Input';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
|
||||
const loginSchema = z.object({
|
||||
email: z.string().email('Please enter a valid email address'),
|
||||
|
||||
@@ -2,8 +2,8 @@
|
||||
|
||||
import Link from 'next/link';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { ThemeToggle } from '@/components/ui/ThemeToggle';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { ThemeToggle } from '@/components/ui/common/ThemeToggle';
|
||||
import { Building2, Beaker, Calendar, Shield, Clock, Users } from 'lucide-react';
|
||||
|
||||
export default function HomePage() {
|
||||
|
||||
@@ -7,8 +7,8 @@ import * as z from 'zod';
|
||||
import Link from 'next/link';
|
||||
import { Building2, Mail, Lock, User, ChevronRight } from 'lucide-react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { Input } from '@/components/ui/Input';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
const registerSchema = z.object({
|
||||
name: z.string().min(2, 'Name must be at least 2 characters'),
|
||||
email: z.string().email('Please enter a valid email address'),
|
||||
@@ -18,6 +18,7 @@ const registerSchema = z.object({
|
||||
.regex(/[0-9]/, 'Password must contain at least one number'),
|
||||
confirmPassword: z.string(),
|
||||
organizationName: z.string().min(2, 'Organization name must be at least 2 characters'),
|
||||
organizationEmail: z.string().email('Please enter a valid organization email'),
|
||||
organizationType: z.enum(['CLINIC', 'LAB'], {
|
||||
message: 'Please select organization type',
|
||||
}),
|
||||
@@ -47,7 +48,7 @@ export default function RegisterPage() {
|
||||
const handleNext = async () => {
|
||||
const fieldsToValidate = step === 1
|
||||
? ['name', 'email', 'password', 'confirmPassword']
|
||||
: ['organizationName', 'organizationType'];
|
||||
: ['organizationName', 'organizationEmail', 'organizationType'];
|
||||
|
||||
const isValid = await trigger(fieldsToValidate as any);
|
||||
if (isValid) {
|
||||
@@ -62,6 +63,7 @@ export default function RegisterPage() {
|
||||
data.password,
|
||||
data.name,
|
||||
data.organizationName,
|
||||
data.organizationEmail,
|
||||
data.organizationType
|
||||
);
|
||||
// No need to redirect - auth context will handle it
|
||||
@@ -182,6 +184,14 @@ export default function RegisterPage() {
|
||||
error={errors.organizationName?.message}
|
||||
icon={<Building2 className="h-5 w-5 icon-flat" />}
|
||||
/>
|
||||
<Input
|
||||
label="Organization email"
|
||||
{...register('organizationEmail')}
|
||||
type="email"
|
||||
placeholder="contact@sunshineclinic.com"
|
||||
error={errors.organizationEmail?.message}
|
||||
icon={<Mail className="h-5 w-5 icon-flat" />}
|
||||
/>
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-text-secondary mb-2">
|
||||
Organization type
|
||||
|
||||
@@ -1,79 +1,12 @@
|
||||
'use client';
|
||||
|
||||
import { useEffect } from 'react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { Building2, Beaker } from 'lucide-react';
|
||||
import { OrganizationSelectorContent } from '@/components/ui/organization/OrganizationSelectorContent';
|
||||
|
||||
export default function SelectOrganizationPage() {
|
||||
const { organizations, selectOrganization, isLoading } = useAuth();
|
||||
|
||||
// ✅ Auto-redirect if only one organization
|
||||
useEffect(() => {
|
||||
if (!isLoading && organizations.length === 1) {
|
||||
selectOrganization(organizations[0].id);
|
||||
}
|
||||
}, [organizations, isLoading]);
|
||||
|
||||
const getIcon = (type: string) => {
|
||||
return type === 'CLINIC'
|
||||
? <Building2 className="h-8 w-8 icon-flat" />
|
||||
: <Beaker className="h-8 w-8 icon-flat" />;
|
||||
};
|
||||
|
||||
if (isLoading) {
|
||||
return (
|
||||
<div className="min-h-screen app-web-bg flex items-center justify-center">
|
||||
<p className="text-text-secondary">Loading organizations...</p>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
if (!organizations.length) {
|
||||
return (
|
||||
<div className="min-h-screen app-web-bg flex items-center justify-center">
|
||||
<p className="text-text-secondary">No organizations found.</p>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="min-h-screen app-web-bg flex items-center justify-center p-4">
|
||||
<div className="max-w-2xl w-full">
|
||||
<div className="text-center mb-8">
|
||||
<h1 className="text-3xl font-semibold text-text-primary">
|
||||
Choose Organization
|
||||
</h1>
|
||||
<p className="text-text-secondary mt-2">
|
||||
You have access to multiple organizations. Select one to continue.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="grid gap-4">
|
||||
{organizations.map((org) => (
|
||||
<button
|
||||
key={org.id}
|
||||
onClick={() => selectOrganization(org.id)}
|
||||
className="surface-card p-6 transition-all text-left flex items-center gap-4 hover:border-primary/60"
|
||||
>
|
||||
<div className="p-3 bg-primary-soft rounded-[var(--radius-sm)] text-primary">
|
||||
{getIcon(org.type)}
|
||||
</div>
|
||||
|
||||
<div className="flex-1">
|
||||
<h3 className="text-lg font-semibold text-text-primary">
|
||||
{org.name}
|
||||
</h3>
|
||||
<p className="text-sm text-text-secondary">
|
||||
{org.type === 'CLINIC' ? 'Dental Clinic' : 'Dental Lab'}
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="text-primary text-sm">
|
||||
Continue →
|
||||
</div>
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
<div className="min-h-screen app-web-bg p-4 sm:p-8">
|
||||
<div className="max-w-3xl mx-auto">
|
||||
<OrganizationSelectorContent />
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
|
||||
@@ -1,61 +0,0 @@
|
||||
'use client';
|
||||
|
||||
import Link from 'next/link';
|
||||
import { memo } from 'react';
|
||||
import { usePathname } from 'next/navigation';
|
||||
import {
|
||||
LayoutDashboard,
|
||||
Users,
|
||||
Calendar,
|
||||
UserCog,
|
||||
FlaskConical,
|
||||
FileText,
|
||||
CreditCard
|
||||
} from 'lucide-react';
|
||||
|
||||
const menu = [
|
||||
{ name: 'Today', path: '/today', icon: LayoutDashboard },
|
||||
{ name: 'Patients', path: '/patients', icon: Users },
|
||||
{ name: 'Appointments', path: '/appointments', icon: Calendar },
|
||||
{ name: 'Staff Management', path: '/staff', icon: UserCog },
|
||||
{ name: 'Lab Management', path: '/lab', icon: FlaskConical },
|
||||
{ name: 'Billing', path: '/billing', icon: CreditCard },
|
||||
{ name: 'Reports', path: '/reports', icon: FileText },
|
||||
];
|
||||
|
||||
function Sidebar() {
|
||||
const pathname = usePathname();
|
||||
|
||||
return (
|
||||
<aside className="w-64 bg-background-secondary/90 border-r border-border text-text-primary flex flex-col p-4">
|
||||
<div className="mb-6 pb-4 border-b border-border">
|
||||
<h1 className="text-xl font-semibold tracking-tight">DyoLink</h1>
|
||||
</div>
|
||||
|
||||
<nav className="flex flex-col gap-2">
|
||||
{menu.map((item) => {
|
||||
const Icon = item.icon;
|
||||
const isActive = pathname === item.path;
|
||||
|
||||
return (
|
||||
<Link
|
||||
key={item.name}
|
||||
href={item.path}
|
||||
prefetch
|
||||
className={`flex items-center gap-3 px-3 py-2.5 rounded-[var(--radius-sm)] border transition-colors ${
|
||||
isActive
|
||||
? 'bg-primary-soft border-primary/60 text-text-primary'
|
||||
: 'border-border/50 text-text-secondary hover:bg-background-card/70 hover:text-text-primary hover:border-border'
|
||||
}`}
|
||||
>
|
||||
<Icon className="w-[18px] h-[18px] icon-flat" />
|
||||
<span className="text-sm">{item.name}</span>
|
||||
</Link>
|
||||
);
|
||||
})}
|
||||
</nav>
|
||||
</aside>
|
||||
);
|
||||
}
|
||||
|
||||
export default memo(Sidebar);
|
||||
70
frontend/src/components/ui/common/Checkbox.tsx
Normal file
70
frontend/src/components/ui/common/Checkbox.tsx
Normal file
@@ -0,0 +1,70 @@
|
||||
'use client';
|
||||
|
||||
import { useId } from 'react';
|
||||
import { Check } from 'lucide-react';
|
||||
|
||||
type CheckboxProps = {
|
||||
checked: boolean;
|
||||
onChange: (checked: boolean) => void;
|
||||
disabled?: boolean;
|
||||
label: string;
|
||||
id?: string;
|
||||
className?: string;
|
||||
};
|
||||
|
||||
/**
|
||||
* App design-system checkbox: primary fill when checked, rounded, focus-visible ring.
|
||||
*/
|
||||
export function Checkbox({
|
||||
checked,
|
||||
onChange,
|
||||
disabled = false,
|
||||
label,
|
||||
id,
|
||||
className = '',
|
||||
}: CheckboxProps) {
|
||||
const genId = useId();
|
||||
const inputId = id ?? genId;
|
||||
|
||||
return (
|
||||
<label
|
||||
htmlFor={inputId}
|
||||
className={`
|
||||
inline-flex items-center gap-2.5 cursor-pointer select-none rounded-[var(--radius-sm)] -m-0.5 p-0.5
|
||||
has-[:focus-visible]:ring-2 has-[:focus-visible]:ring-primary/45 has-[:focus-visible]:ring-offset-2
|
||||
has-[:focus-visible]:ring-offset-background-secondary
|
||||
${disabled ? 'opacity-50 cursor-not-allowed' : ''}
|
||||
${className}
|
||||
`}
|
||||
>
|
||||
<input
|
||||
id={inputId}
|
||||
type="checkbox"
|
||||
className="sr-only"
|
||||
checked={checked}
|
||||
disabled={disabled}
|
||||
onChange={(e) => onChange(e.target.checked)}
|
||||
/>
|
||||
<span
|
||||
className={`
|
||||
flex h-5 w-5 shrink-0 items-center justify-center rounded-[var(--radius-sm)] border-2 transition-all duration-200
|
||||
shadow-[inset_0_1px_0_rgba(255,255,255,0.05)]
|
||||
${
|
||||
checked
|
||||
? 'border-primary bg-primary shadow-[0_0_0_1px_rgba(9,169,188,0.25)]'
|
||||
: 'border-border-strong bg-background-card/90 hover:border-border'
|
||||
}
|
||||
`}
|
||||
aria-hidden
|
||||
>
|
||||
<Check
|
||||
strokeWidth={3}
|
||||
className={`h-3.5 w-3.5 text-primary-contrast transition-all duration-200 ${
|
||||
checked ? 'scale-100 opacity-100' : 'scale-75 opacity-0'
|
||||
}`}
|
||||
/>
|
||||
</span>
|
||||
<span className="text-sm text-text-secondary">{label}</span>
|
||||
</label>
|
||||
);
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
// src/components/ui/OrganizationCard.tsx
|
||||
import React from 'react';
|
||||
import { Building2, Beaker, ChevronRight } from 'lucide-react';
|
||||
import { Organization } from '@/types';
|
||||
import type { Organization } from '@/types/organization';
|
||||
|
||||
interface OrganizationCardProps {
|
||||
organization: Organization;
|
||||
70
frontend/src/components/ui/common/Sidebar.tsx
Normal file
70
frontend/src/components/ui/common/Sidebar.tsx
Normal file
@@ -0,0 +1,70 @@
|
||||
'use client';
|
||||
|
||||
import Link from 'next/link';
|
||||
import { memo, useMemo } from 'react';
|
||||
import { usePathname } from 'next/navigation';
|
||||
import {
|
||||
LayoutDashboard,
|
||||
Users,
|
||||
Calendar,
|
||||
UserCog,
|
||||
FlaskConical,
|
||||
FileText,
|
||||
CreditCard,
|
||||
} from 'lucide-react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { canViewTab } from '@/shared/permissions';
|
||||
|
||||
const menu = [
|
||||
{ name: 'Today', path: '/today', icon: LayoutDashboard, read: 'TAB_TODAY_READ' as const },
|
||||
{ name: 'Patients', path: '/patients', icon: Users, read: 'TAB_PATIENTS_READ' as const },
|
||||
{ name: 'Appointments', path: '/appointments', icon: Calendar, read: 'TAB_APPOINTMENTS_READ' as const },
|
||||
{ name: 'Staff Management', path: '/staff', icon: UserCog, read: 'TAB_STAFF_READ' as const },
|
||||
{ name: 'Lab Management', path: '/lab', icon: FlaskConical, read: 'TAB_LAB_READ' as const },
|
||||
{ name: 'Billing', path: '/billing', icon: CreditCard, read: 'TAB_BILLING_READ' as const },
|
||||
{ name: 'Reports', path: '/reports', icon: FileText, read: 'TAB_REPORTS_READ' as const },
|
||||
];
|
||||
|
||||
function Sidebar() {
|
||||
const pathname = usePathname();
|
||||
const { currentOrganization } = useAuth();
|
||||
|
||||
const visibleMenu = useMemo(
|
||||
() => menu.filter((item) => canViewTab(currentOrganization, item.read)),
|
||||
[currentOrganization],
|
||||
);
|
||||
|
||||
return (
|
||||
<aside className="w-64 bg-background-secondary/90 border-r border-border text-text-primary flex flex-col">
|
||||
<div className="h-[71px] px-4 flex items-center">
|
||||
<h1 className="text-lg font-medium tracking-tight">DyoLink</h1>
|
||||
</div>
|
||||
<div className="mx-4 border-b border-border/70" />
|
||||
|
||||
<nav className="flex flex-col gap-2 p-4">
|
||||
{visibleMenu.map((item) => {
|
||||
const Icon = item.icon;
|
||||
const isActive = pathname === item.path;
|
||||
|
||||
return (
|
||||
<Link
|
||||
key={item.name}
|
||||
href={item.path}
|
||||
prefetch
|
||||
className={`flex items-center gap-3 px-3 py-2.5 rounded-[var(--radius-sm)] border transition-colors ${
|
||||
isActive
|
||||
? 'bg-primary-soft border-primary/60 text-text-primary'
|
||||
: 'border-border/50 text-text-secondary hover:bg-background-card/70 hover:text-text-primary hover:border-border'
|
||||
}`}
|
||||
>
|
||||
<Icon className="w-[18px] h-[18px] icon-flat" />
|
||||
<span className="text-sm">{item.name}</span>
|
||||
</Link>
|
||||
);
|
||||
})}
|
||||
</nav>
|
||||
</aside>
|
||||
);
|
||||
}
|
||||
|
||||
export default memo(Sidebar);
|
||||
156
frontend/src/components/ui/dashboard/DashboardAccountMenu.tsx
Normal file
156
frontend/src/components/ui/dashboard/DashboardAccountMenu.tsx
Normal file
@@ -0,0 +1,156 @@
|
||||
'use client';
|
||||
|
||||
import { useCallback, useEffect, useMemo, useRef, useState } from 'react';
|
||||
import Link from 'next/link';
|
||||
import {
|
||||
Settings,
|
||||
AlertTriangle,
|
||||
Building2,
|
||||
CreditCard,
|
||||
User,
|
||||
LogOut,
|
||||
ChevronDown,
|
||||
} from 'lucide-react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { authApi } from '@/lib/api/auth';
|
||||
import type { SubscriptionAlertData } from '@/types/subscription';
|
||||
|
||||
function warningTooltip(data: SubscriptionAlertData | null): string {
|
||||
if (!data?.showWarning) return '';
|
||||
if (data.trialExpired) return 'Trial ended — review Subscriptions';
|
||||
if (data.trialEndingSoon) return 'Trial ending soon — review Subscriptions';
|
||||
if (data.seatsLow) return 'Seats running low — review Subscriptions';
|
||||
return 'Review Subscriptions';
|
||||
}
|
||||
|
||||
export function DashboardAccountMenu() {
|
||||
const { user, currentOrganization, logout } = useAuth();
|
||||
const [open, setOpen] = useState(false);
|
||||
const menuRef = useRef<HTMLDivElement>(null);
|
||||
const [alert, setAlert] = useState<SubscriptionAlertData | null>(null);
|
||||
const isOwner = currentOrganization?.isOwner ?? false;
|
||||
|
||||
useEffect(() => {
|
||||
const onDocClick = (e: MouseEvent) => {
|
||||
if (menuRef.current && !menuRef.current.contains(e.target as Node)) {
|
||||
setOpen(false);
|
||||
}
|
||||
};
|
||||
document.addEventListener('mousedown', onDocClick);
|
||||
return () => document.removeEventListener('mousedown', onDocClick);
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
if (!isOwner || !currentOrganization) {
|
||||
setAlert(null);
|
||||
return;
|
||||
}
|
||||
let cancelled = false;
|
||||
void (async () => {
|
||||
try {
|
||||
const res = await authApi.getSubscriptionAlert();
|
||||
if (!cancelled && res.success) setAlert(res.data);
|
||||
} catch {
|
||||
if (!cancelled) setAlert(null);
|
||||
}
|
||||
})();
|
||||
return () => {
|
||||
cancelled = true;
|
||||
};
|
||||
}, [isOwner, currentOrganization?.id]);
|
||||
|
||||
const showWarning = Boolean(isOwner && alert?.showWarning);
|
||||
const tooltip = useMemo(() => warningTooltip(alert), [alert]);
|
||||
|
||||
const handleLogout = useCallback(() => {
|
||||
setOpen(false);
|
||||
void logout();
|
||||
}, [logout]);
|
||||
|
||||
return (
|
||||
<div className="relative z-[120]" ref={menuRef}>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setOpen((v) => !v)}
|
||||
className="inline-flex items-center gap-2 rounded-[var(--radius-md)] border border-border/70 px-3 py-2 text-sm text-text-primary hover:bg-background-card/80 transition-colors"
|
||||
aria-expanded={open}
|
||||
aria-haspopup="menu"
|
||||
>
|
||||
<span className="relative inline-flex shrink-0" title={showWarning ? tooltip : undefined}>
|
||||
<Settings className="h-5 w-5 icon-flat" aria-hidden />
|
||||
{showWarning && (
|
||||
<span
|
||||
className="absolute -right-1 -top-1 flex h-3.5 w-3.5 items-center justify-center rounded-full bg-amber-500 ring-2 ring-background-secondary"
|
||||
aria-label={tooltip}
|
||||
>
|
||||
<AlertTriangle className="h-2.5 w-2.5 text-amber-950" strokeWidth={2.5} />
|
||||
</span>
|
||||
)}
|
||||
</span>
|
||||
<span className="hidden sm:inline max-w-[160px] truncate">{user?.name}</span>
|
||||
<ChevronDown className="h-4 w-4 text-text-muted shrink-0" aria-hidden />
|
||||
</button>
|
||||
|
||||
{open && (
|
||||
<div
|
||||
role="menu"
|
||||
className="absolute right-0 mt-2 w-72 rounded-[var(--radius-md)] border border-border bg-background-secondary/95 py-2 shadow-lg z-[200] backdrop-blur-sm"
|
||||
>
|
||||
<div className="px-3 py-2 border-b border-border/60">
|
||||
<p className="text-xs text-text-muted">Signed in</p>
|
||||
<p className="text-sm font-medium truncate">{user?.email}</p>
|
||||
<p className="text-xs text-text-secondary mt-1 truncate">
|
||||
{currentOrganization?.name}
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="py-1">
|
||||
<Link
|
||||
href="/settings/organizations"
|
||||
role="menuitem"
|
||||
className="flex items-center gap-3 px-3 py-2.5 text-sm text-text-primary hover:bg-background-card/70"
|
||||
onClick={() => setOpen(false)}
|
||||
>
|
||||
<Building2 className="h-4 w-4 icon-flat shrink-0" />
|
||||
Switch organization
|
||||
</Link>
|
||||
|
||||
{isOwner && (
|
||||
<Link
|
||||
href="/settings/subscriptions"
|
||||
role="menuitem"
|
||||
className="flex items-center gap-3 px-3 py-2.5 text-sm text-text-primary hover:bg-background-card/70"
|
||||
onClick={() => setOpen(false)}
|
||||
>
|
||||
<CreditCard className="h-4 w-4 icon-flat shrink-0" />
|
||||
Subscriptions
|
||||
</Link>
|
||||
)}
|
||||
|
||||
<Link
|
||||
href="/settings/account"
|
||||
role="menuitem"
|
||||
className="flex items-center gap-3 px-3 py-2.5 text-sm text-text-primary hover:bg-background-card/70"
|
||||
onClick={() => setOpen(false)}
|
||||
>
|
||||
<User className="h-4 w-4 icon-flat shrink-0" />
|
||||
Account
|
||||
</Link>
|
||||
</div>
|
||||
|
||||
<div className="border-t border-border/60 pt-1">
|
||||
<button
|
||||
type="button"
|
||||
role="menuitem"
|
||||
className="flex w-full items-center gap-3 px-3 py-2.5 text-sm text-text-secondary hover:bg-background-card/70 hover:text-text-primary"
|
||||
onClick={handleLogout}
|
||||
>
|
||||
<LogOut className="h-4 w-4 icon-flat shrink-0" />
|
||||
Log out
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,162 @@
|
||||
'use client';
|
||||
|
||||
import { useState } from 'react';
|
||||
import { useAuth } from '@/lib/hooks/useAuth';
|
||||
import { Building2, Beaker, Mail, Plus } from 'lucide-react';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
|
||||
export function OrganizationSelectorContent() {
|
||||
const { organizations, selectOrganization, createOrganization, isLoading, error, clearError } = useAuth();
|
||||
const [isCreateOpen, setIsCreateOpen] = useState(false);
|
||||
const [organizationName, setOrganizationName] = useState('');
|
||||
const [organizationEmail, setOrganizationEmail] = useState('');
|
||||
const [organizationType, setOrganizationType] = useState<'CLINIC' | 'LAB'>('CLINIC');
|
||||
|
||||
const getIcon = (type: string) =>
|
||||
type === 'CLINIC' ? <Building2 className="h-8 w-8 icon-flat" /> : <Beaker className="h-8 w-8 icon-flat" />;
|
||||
|
||||
const handleCreateOrganization = async () => {
|
||||
try {
|
||||
clearError();
|
||||
const createdId = await createOrganization(
|
||||
organizationName.trim(),
|
||||
organizationEmail.trim(),
|
||||
organizationType,
|
||||
);
|
||||
setOrganizationName('');
|
||||
setOrganizationEmail('');
|
||||
setOrganizationType('CLINIC');
|
||||
setIsCreateOpen(false);
|
||||
await selectOrganization(createdId);
|
||||
} catch {
|
||||
// handled by auth context
|
||||
}
|
||||
};
|
||||
|
||||
if (isLoading) {
|
||||
return <p className="text-text-secondary">Loading...</p>;
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="space-y-6">
|
||||
<div className="flex flex-col sm:flex-row sm:items-center sm:justify-between gap-4">
|
||||
<div>
|
||||
<h1 className="text-3xl font-semibold text-text-primary">Organizations</h1>
|
||||
<p className="text-text-secondary mt-2">
|
||||
Select an organization to continue, or create a new one.
|
||||
</p>
|
||||
</div>
|
||||
<Button
|
||||
type="button"
|
||||
variant={isCreateOpen ? 'outline' : 'primary'}
|
||||
onClick={() => {
|
||||
clearError();
|
||||
setIsCreateOpen((prev) => !prev);
|
||||
}}
|
||||
>
|
||||
<Plus className="h-4 w-4 mr-2 icon-flat" />
|
||||
{isCreateOpen ? 'Cancel' : 'Create Organization'}
|
||||
</Button>
|
||||
</div>
|
||||
|
||||
{isCreateOpen && (
|
||||
<div className="surface-card p-6 space-y-4">
|
||||
<Input
|
||||
label="Organization name"
|
||||
value={organizationName}
|
||||
onChange={(event) => setOrganizationName(event.target.value)}
|
||||
placeholder="Sunshine Dental Clinic"
|
||||
icon={<Building2 className="h-5 w-5 icon-flat" />}
|
||||
/>
|
||||
<Input
|
||||
label="Organization email"
|
||||
value={organizationEmail}
|
||||
onChange={(event) => setOrganizationEmail(event.target.value)}
|
||||
placeholder="contact@sunshineclinic.com"
|
||||
type="email"
|
||||
icon={<Mail className="h-5 w-5 icon-flat" />}
|
||||
/>
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-text-secondary mb-2">
|
||||
Organization type
|
||||
</label>
|
||||
<div className="grid grid-cols-2 gap-3">
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setOrganizationType('CLINIC')}
|
||||
className={`p-3 border rounded-[var(--radius-md)] text-sm ${
|
||||
organizationType === 'CLINIC'
|
||||
? 'border-primary/60 bg-primary-soft text-text-primary'
|
||||
: 'border-border text-text-secondary hover:border-border-strong'
|
||||
}`}
|
||||
>
|
||||
Dental Clinic
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setOrganizationType('LAB')}
|
||||
className={`p-3 border rounded-[var(--radius-md)] text-sm ${
|
||||
organizationType === 'LAB'
|
||||
? 'border-primary/60 bg-primary-soft text-text-primary'
|
||||
: 'border-border text-text-secondary hover:border-border-strong'
|
||||
}`}
|
||||
>
|
||||
Dental Lab
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
{error && (
|
||||
<div className="p-3 bg-red-950/30 border border-red-600/40 rounded-[var(--radius-md)]">
|
||||
<p className="text-sm text-red-600">{error}</p>
|
||||
</div>
|
||||
)}
|
||||
<div className="flex justify-end">
|
||||
<Button
|
||||
type="button"
|
||||
variant="primary"
|
||||
onClick={handleCreateOrganization}
|
||||
isLoading={isLoading}
|
||||
disabled={!organizationName.trim() || !organizationEmail.trim()}
|
||||
>
|
||||
Create and Continue
|
||||
</Button>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{!organizations.length ? (
|
||||
<div className="surface-card p-8 text-center">
|
||||
<p className="text-text-secondary">No organizations found. Create your first one to continue.</p>
|
||||
</div>
|
||||
) : (
|
||||
<div className="grid gap-4">
|
||||
{organizations.map((org) => (
|
||||
<button
|
||||
key={org.id}
|
||||
onClick={() => selectOrganization(org.id)}
|
||||
className="surface-card p-6 transition-all text-left flex items-center gap-4 hover:border-primary/60"
|
||||
>
|
||||
<div className="p-3 bg-primary-soft rounded-[var(--radius-sm)] text-primary">
|
||||
{getIcon(org.type)}
|
||||
</div>
|
||||
|
||||
<div className="flex-1">
|
||||
<h3 className="text-lg font-semibold text-text-primary">
|
||||
{org.name}
|
||||
</h3>
|
||||
<p className="text-sm text-text-secondary">
|
||||
{org.type === 'CLINIC' ? 'Dental Clinic' : 'Dental Lab'}
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="text-primary text-sm">
|
||||
Continue →
|
||||
</div>
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
'use client';
|
||||
|
||||
import { Button } from '@/components/ui/Button';
|
||||
import { Input } from '@/components/ui/Input';
|
||||
import { Button } from '@/components/ui/common/Button';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { CreatePatientInput } from '@/types/patient';
|
||||
|
||||
interface CreatePatientModalProps {
|
||||
@@ -1,7 +1,7 @@
|
||||
'use client';
|
||||
|
||||
import { Search } from 'lucide-react';
|
||||
import { Input } from '@/components/ui/Input';
|
||||
import { Input } from '@/components/ui/common/Input';
|
||||
import { Patient } from '@/types/patient';
|
||||
|
||||
interface PatientSearchSelectProps {
|
||||
@@ -1,6 +1,7 @@
|
||||
// src/lib/api/auth.ts
|
||||
import { apiClient } from './client';
|
||||
import { AuthResponse, TrialRegistrationData, LoginData } from '@/types';
|
||||
import type { AuthResponse, TrialRegistrationData, LoginData } from '@/types/auth';
|
||||
import type { SubscriptionAlertData } from '@/types/subscription';
|
||||
|
||||
export const authApi = {
|
||||
// Register a new trial organization
|
||||
@@ -21,12 +22,32 @@ export const authApi = {
|
||||
return response.data;
|
||||
},
|
||||
|
||||
/** Owner-only meaningful data; staff always gets showWarning: false */
|
||||
getSubscriptionAlert: async (): Promise<{
|
||||
success: boolean;
|
||||
data: SubscriptionAlertData;
|
||||
}> => {
|
||||
const response = await apiClient.get('/auth/subscription-alert');
|
||||
return response.data;
|
||||
},
|
||||
|
||||
// Select organization
|
||||
selectOrganization: async (organizationId: string): Promise<any> => {
|
||||
const response = await apiClient.post('/auth/select-organization', { organizationId });
|
||||
return response.data;
|
||||
},
|
||||
|
||||
// Create organization for current user
|
||||
createOrganization: async (data: {
|
||||
organizationName: string;
|
||||
organizationEmail: string;
|
||||
organizationType: 'CLINIC' | 'LAB';
|
||||
planName?: string;
|
||||
}): Promise<any> => {
|
||||
const response = await apiClient.post('/auth/organizations', data);
|
||||
return response.data;
|
||||
},
|
||||
|
||||
// Logout
|
||||
logout: async (): Promise<void> => {
|
||||
await apiClient.post('/auth/logout');
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
// src/lib/api/client.ts
|
||||
import axios, { AxiosError, InternalAxiosRequestConfig } from 'axios';
|
||||
import { ApiError } from '@/types';
|
||||
import type { ApiError } from '@/types/api';
|
||||
|
||||
interface CustomAxiosRequestConfig extends InternalAxiosRequestConfig {
|
||||
_retry?: boolean;
|
||||
|
||||
94
frontend/src/lib/api/staff.ts
Normal file
94
frontend/src/lib/api/staff.ts
Normal file
@@ -0,0 +1,94 @@
|
||||
import { apiClient } from './client';
|
||||
|
||||
export interface StaffMemberDto {
|
||||
id: string;
|
||||
userId: string;
|
||||
email: string;
|
||||
name: string;
|
||||
isOwner: boolean;
|
||||
isActive: boolean;
|
||||
invitationStatus: 'ACTIVE' | 'PENDING' | 'EXPIRED';
|
||||
invitedAt: string | null;
|
||||
acceptedAt: string | null;
|
||||
permissions: string[] | null;
|
||||
}
|
||||
|
||||
export interface StaffListResponse {
|
||||
success: boolean;
|
||||
data: {
|
||||
members: StaffMemberDto[];
|
||||
seats: {
|
||||
used: number;
|
||||
limit: number | null;
|
||||
unlimited: boolean;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
export interface InviteStaffResponse {
|
||||
success: boolean;
|
||||
data: {
|
||||
membershipId: string;
|
||||
userId: string;
|
||||
email: string;
|
||||
invitationId: string | null;
|
||||
invitationUrl: string | null;
|
||||
invitationStatus: 'PENDING' | 'ACCEPTED';
|
||||
};
|
||||
}
|
||||
|
||||
export interface PreviewInviteResponse {
|
||||
success: boolean;
|
||||
data: {
|
||||
email: string;
|
||||
name: string;
|
||||
organizationName: string;
|
||||
expiresAt: string;
|
||||
status: 'PENDING' | 'ACCEPTED';
|
||||
};
|
||||
}
|
||||
|
||||
export const staffApi = {
|
||||
list: async (): Promise<StaffListResponse> => {
|
||||
const response = await apiClient.get('/staff');
|
||||
return response.data;
|
||||
},
|
||||
|
||||
invite: async (body: {
|
||||
email: string;
|
||||
name: string;
|
||||
permissionNames: string[];
|
||||
}): Promise<InviteStaffResponse> => {
|
||||
const response = await apiClient.post('/staff/invite', body);
|
||||
return response.data;
|
||||
},
|
||||
|
||||
previewInvite: async (token: string): Promise<PreviewInviteResponse> => {
|
||||
const response = await apiClient.get(`/staff/invitations/preview?token=${encodeURIComponent(token)}`);
|
||||
return response.data;
|
||||
},
|
||||
|
||||
acceptInvite: async (body: {
|
||||
token: string;
|
||||
password: string;
|
||||
name: string;
|
||||
}): Promise<{ success: boolean; message: string; data: { email: string } }> => {
|
||||
const response = await apiClient.post('/staff/invitations/accept', body);
|
||||
return response.data;
|
||||
},
|
||||
|
||||
updateMember: async (
|
||||
membershipId: string,
|
||||
body: { name?: string; permissionNames?: string[] },
|
||||
): Promise<{ success: boolean; message: string }> => {
|
||||
const response = await apiClient.patch(`/staff/members/${membershipId}`, body);
|
||||
return response.data;
|
||||
},
|
||||
|
||||
removeMember: async (
|
||||
membershipId: string,
|
||||
): Promise<{ success: boolean; message: string }> => {
|
||||
const response = await apiClient.delete(`/staff/members/${membershipId}`);
|
||||
return response.data;
|
||||
},
|
||||
};
|
||||
@@ -3,7 +3,7 @@
|
||||
import React, { createContext, useCallback, useContext, useEffect, useMemo, useState } from 'react';
|
||||
import { useRouter } from 'next/navigation';
|
||||
import { authApi } from '@/lib/api/auth';
|
||||
import { User, Organization } from '@/types';
|
||||
import { User, Organization } from '@/types/organization';
|
||||
|
||||
interface AuthContextType {
|
||||
user: User | null;
|
||||
@@ -17,11 +17,18 @@ interface AuthContextType {
|
||||
password: string,
|
||||
name: string,
|
||||
organizationName: string,
|
||||
organizationEmail: string,
|
||||
organizationType: 'CLINIC' | 'LAB'
|
||||
) => Promise<void>;
|
||||
login: (email: string, password: string) => Promise<void>;
|
||||
logout: () => Promise<void>;
|
||||
selectOrganization: (orgId: string) => Promise<void>;
|
||||
createOrganization: (
|
||||
organizationName: string,
|
||||
organizationEmail: string,
|
||||
organizationType: 'CLINIC' | 'LAB',
|
||||
planName?: string,
|
||||
) => Promise<string>;
|
||||
clearError: () => void;
|
||||
}
|
||||
|
||||
@@ -111,6 +118,7 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
password: string,
|
||||
name: string,
|
||||
organizationName: string,
|
||||
organizationEmail: string,
|
||||
organizationType: 'CLINIC' | 'LAB'
|
||||
) => {
|
||||
try {
|
||||
@@ -122,6 +130,7 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
password,
|
||||
name,
|
||||
organizationName,
|
||||
organizationEmail,
|
||||
organizationType,
|
||||
});
|
||||
|
||||
@@ -209,7 +218,14 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
|
||||
localStorage.setItem('currentOrganizationId', organization.id);
|
||||
|
||||
setCurrentOrganization(organization);
|
||||
setCurrentOrganization({
|
||||
id: organization.id,
|
||||
name: organization.name,
|
||||
type: organization.type as Organization['type'],
|
||||
isOwner: Boolean((organization as { isOwner?: boolean }).isOwner),
|
||||
permissions: (organization as { permissions?: string[] }).permissions,
|
||||
plan: (organization as { plan?: Organization['plan'] }).plan,
|
||||
});
|
||||
|
||||
router.push('/today');
|
||||
|
||||
@@ -221,6 +237,39 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
}
|
||||
}, [router]);
|
||||
|
||||
const createOrganization = useCallback(async (
|
||||
organizationName: string,
|
||||
organizationEmail: string,
|
||||
organizationType: 'CLINIC' | 'LAB',
|
||||
planName?: string,
|
||||
) => {
|
||||
try {
|
||||
setIsLoading(true);
|
||||
setError(null);
|
||||
|
||||
const createResponse = await authApi.createOrganization({
|
||||
organizationName,
|
||||
organizationEmail,
|
||||
organizationType,
|
||||
planName,
|
||||
});
|
||||
|
||||
const profileResponse = await authApi.getProfile();
|
||||
if (profileResponse.success) {
|
||||
const { user: userData, organizations: orgs } = normalizeProfilePayload(profileResponse.data);
|
||||
setUser(userData);
|
||||
setOrganizations(orgs);
|
||||
}
|
||||
|
||||
return createResponse.data.organization.id as string;
|
||||
} catch (err: any) {
|
||||
setError(err.message || 'Failed to create organization');
|
||||
throw err;
|
||||
} finally {
|
||||
setIsLoading(false);
|
||||
}
|
||||
}, [normalizeProfilePayload]);
|
||||
|
||||
const clearError = useCallback(() => setError(null), []);
|
||||
|
||||
const contextValue = useMemo(
|
||||
@@ -235,6 +284,7 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
login,
|
||||
logout,
|
||||
selectOrganization,
|
||||
createOrganization,
|
||||
clearError,
|
||||
}),
|
||||
[
|
||||
@@ -248,6 +298,7 @@ export function AuthProvider({ children }: { children: React.ReactNode }) {
|
||||
login,
|
||||
logout,
|
||||
selectOrganization,
|
||||
createOrganization,
|
||||
clearError,
|
||||
],
|
||||
);
|
||||
|
||||
@@ -1,32 +1,22 @@
|
||||
|
||||
import { NextResponse } from 'next/server';
|
||||
import type { NextRequest } from 'next/server';
|
||||
|
||||
const publicRoutes = ['/', '/login', '/register', '/terms', '/privacy', '/forgot-password'];
|
||||
const authOnlyRoutes = ['/login', '/register']; // routes that should NOT be accessed when logged in
|
||||
|
||||
export function middleware(request: NextRequest) {
|
||||
export function proxy(request: NextRequest) {
|
||||
const { pathname } = request.nextUrl;
|
||||
const token = request.cookies.get('accessToken')?.value;
|
||||
const isAuthenticated = !!token;
|
||||
|
||||
// If a logged-in user opens home, send them to dashboard.
|
||||
if (isAuthenticated && pathname === '/') {
|
||||
return NextResponse.redirect(new URL('/today', request.url));
|
||||
}
|
||||
|
||||
// Always allow public routes first
|
||||
if (publicRoutes.includes(pathname)) {
|
||||
// If user is already logged in and tries to access login/register → redirect to dashboard
|
||||
if (isAuthenticated && authOnlyRoutes.includes(pathname)) {
|
||||
return NextResponse.redirect(new URL('/today', request.url));
|
||||
}
|
||||
return NextResponse.next();
|
||||
}
|
||||
|
||||
// Protected routes: redirect to login if no token
|
||||
if (!isAuthenticated) {
|
||||
// Prevent loop: if somehow redirecting to login from login, just continue
|
||||
if (pathname === '/login') {
|
||||
return NextResponse.next();
|
||||
}
|
||||
@@ -43,4 +33,4 @@ export const config = {
|
||||
matcher: [
|
||||
'/((?!_next/static|_next/image|favicon.ico|.*\\.(?:svg|png|jpg|jpeg|gif|webp)$).*)',
|
||||
],
|
||||
};
|
||||
};
|
||||
51
frontend/src/shared/permissions.ts
Normal file
51
frontend/src/shared/permissions.ts
Normal file
@@ -0,0 +1,51 @@
|
||||
import type { Organization } from '@/types/organization';
|
||||
|
||||
const ROUTE_TAB_READ: { prefix: string; permission: string }[] = [
|
||||
{ prefix: '/today', permission: 'TAB_TODAY_READ' },
|
||||
{ prefix: '/patients', permission: 'TAB_PATIENTS_READ' },
|
||||
{ prefix: '/appointments', permission: 'TAB_APPOINTMENTS_READ' },
|
||||
{ prefix: '/staff', permission: 'TAB_STAFF_READ' },
|
||||
{ prefix: '/lab', permission: 'TAB_LAB_READ' },
|
||||
{ prefix: '/billing', permission: 'TAB_BILLING_READ' },
|
||||
{ prefix: '/reports', permission: 'TAB_REPORTS_READ' },
|
||||
];
|
||||
|
||||
export function hasPermission(org: Organization | null, permission: string): boolean {
|
||||
if (!org) return false;
|
||||
if (org.isOwner) return true;
|
||||
return Boolean(org.permissions?.includes(permission));
|
||||
}
|
||||
|
||||
/** Sidebar / route guard: READ access to a tab */
|
||||
export function canViewTab(org: Organization | null, readPermission: string): boolean {
|
||||
return hasPermission(org, readPermission);
|
||||
}
|
||||
|
||||
export function getRequiredReadPermissionForPath(pathname: string): string | null {
|
||||
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||
if (pathname === prefix || pathname.startsWith(`${prefix}/`)) {
|
||||
return permission;
|
||||
}
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/** First dashboard route the user may open (ordered). Fallback: account settings. */
|
||||
export function firstAccessibleDashboardPath(org: Organization | null): string {
|
||||
if (!org) return '/today';
|
||||
if (org.isOwner) return '/today';
|
||||
for (const { prefix, permission } of ROUTE_TAB_READ) {
|
||||
if (hasPermission(org, permission)) return prefix;
|
||||
}
|
||||
return '/settings/account';
|
||||
}
|
||||
|
||||
export function canEditStaff(org: Organization | null): boolean {
|
||||
return hasPermission(org, 'TAB_STAFF_EDIT');
|
||||
}
|
||||
|
||||
export function canViewStaff(org: Organization | null): boolean {
|
||||
return (
|
||||
hasPermission(org, 'TAB_STAFF_READ') || hasPermission(org, 'TAB_STAFF_EDIT')
|
||||
);
|
||||
}
|
||||
@@ -2,9 +2,9 @@
|
||||
|
||||
/* Light theme tokens (future-ready) */
|
||||
:root[data-theme="light"] {
|
||||
--radius-sm: 6px;
|
||||
--radius-md: 8px;
|
||||
--radius-lg: 12px;
|
||||
--radius-sm: 4px;
|
||||
--radius-md: 6px;
|
||||
--radius-lg: 8px;
|
||||
|
||||
--color-background-primary: #f6f9fc;
|
||||
--color-background-secondary: #ffffff;
|
||||
@@ -45,7 +45,7 @@
|
||||
--color-primary: #09a9bc;
|
||||
--color-primary-contrast: #001117;
|
||||
--color-primary-soft: rgba(9, 169, 188, 0.2);
|
||||
--color-icon: #f3bb4b;
|
||||
--color-icon: #e1bc72;
|
||||
}
|
||||
|
||||
/* Default theme = dark */
|
||||
|
||||
5
frontend/src/types/api.ts
Normal file
5
frontend/src/types/api.ts
Normal file
@@ -0,0 +1,5 @@
|
||||
export interface ApiError {
|
||||
statusCode: number;
|
||||
message: string | string[];
|
||||
error?: string;
|
||||
}
|
||||
25
frontend/src/types/auth.ts
Normal file
25
frontend/src/types/auth.ts
Normal file
@@ -0,0 +1,25 @@
|
||||
import type { Organization, User } from './organization';
|
||||
|
||||
export interface AuthResponse {
|
||||
success: boolean;
|
||||
data: {
|
||||
accessToken: string;
|
||||
refreshToken: string;
|
||||
user: User;
|
||||
organizations: Organization[];
|
||||
};
|
||||
}
|
||||
|
||||
export interface TrialRegistrationData {
|
||||
email: string;
|
||||
password: string;
|
||||
name: string;
|
||||
organizationName: string;
|
||||
organizationEmail: string;
|
||||
organizationType: 'CLINIC' | 'LAB';
|
||||
}
|
||||
|
||||
export interface LoginData {
|
||||
email: string;
|
||||
password: string;
|
||||
}
|
||||
@@ -1,46 +1,5 @@
|
||||
// src/types/index.ts
|
||||
export interface User {
|
||||
id: string;
|
||||
email: string;
|
||||
name: string;
|
||||
}
|
||||
|
||||
export interface Organization {
|
||||
id: string;
|
||||
name: string;
|
||||
type: 'CLINIC' | 'LAB';
|
||||
isOwner: boolean;
|
||||
plan?: {
|
||||
name: string;
|
||||
maxUsers: number;
|
||||
};
|
||||
}
|
||||
|
||||
export interface AuthResponse {
|
||||
success: boolean;
|
||||
data: {
|
||||
accessToken: string;
|
||||
refreshToken: string;
|
||||
user: User;
|
||||
organizations: Organization[];
|
||||
};
|
||||
}
|
||||
|
||||
export interface TrialRegistrationData {
|
||||
email: string;
|
||||
password: string;
|
||||
name: string;
|
||||
organizationName: string;
|
||||
organizationType: 'CLINIC' | 'LAB';
|
||||
}
|
||||
|
||||
export interface LoginData {
|
||||
email: string;
|
||||
password: string;
|
||||
}
|
||||
|
||||
export interface ApiError {
|
||||
statusCode: number;
|
||||
message: string | string[];
|
||||
error?: string;
|
||||
}
|
||||
export * from './organization';
|
||||
export * from './subscription';
|
||||
export * from './auth';
|
||||
export * from './api';
|
||||
export * from './patient';
|
||||
20
frontend/src/types/organization.ts
Normal file
20
frontend/src/types/organization.ts
Normal file
@@ -0,0 +1,20 @@
|
||||
export interface User {
|
||||
id: string;
|
||||
email: string;
|
||||
name: string;
|
||||
}
|
||||
|
||||
export interface OrganizationPlan {
|
||||
name: string;
|
||||
maxUsers: number;
|
||||
price?: number;
|
||||
}
|
||||
|
||||
export interface Organization {
|
||||
id: string;
|
||||
name: string;
|
||||
type: 'CLINIC' | 'LAB';
|
||||
isOwner: boolean;
|
||||
permissions?: string[];
|
||||
plan?: OrganizationPlan;
|
||||
}
|
||||
13
frontend/src/types/subscription.ts
Normal file
13
frontend/src/types/subscription.ts
Normal file
@@ -0,0 +1,13 @@
|
||||
/** GET /auth/subscription-alert — owners only get meaningful flags */
|
||||
export interface SubscriptionAlertData {
|
||||
showWarning: boolean;
|
||||
seatsLow: boolean;
|
||||
trialEndingSoon: boolean;
|
||||
trialExpired: boolean;
|
||||
seatsUsed?: number;
|
||||
seatsLimit?: number;
|
||||
daysUntilTrialEnd?: number | null;
|
||||
trialEndsAt?: string | null;
|
||||
daysUntilPlanEnd?: number | null;
|
||||
planEndsAt?: string | null;
|
||||
}
|
||||
Reference in New Issue
Block a user