chore(seed): grant admin page permissions to built-in roles
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
parent
822ac47c23
commit
37d82fd711
1 changed files with 72 additions and 30 deletions
|
|
@ -2,6 +2,17 @@ import { getPayload } from "payload";
|
||||||
import config from "@payload-config";
|
import config from "@payload-config";
|
||||||
import type { Permission } from "@/permissions";
|
import type { Permission } from "@/permissions";
|
||||||
|
|
||||||
|
const resolvedConfig = await config;
|
||||||
|
const COLLECTION_SLUGS = resolvedConfig.collections.map((c) => c.slug);
|
||||||
|
|
||||||
|
const ALL_COLLECTION_READS: Permission[] = COLLECTION_SLUGS.map(
|
||||||
|
(slug) => `${slug}:read` as Permission,
|
||||||
|
);
|
||||||
|
|
||||||
|
const ALL_ADMIN_PAGE_MANAGE: Permission[] = COLLECTION_SLUGS.map(
|
||||||
|
(slug) => `admin:${slug}:manage` as Permission,
|
||||||
|
);
|
||||||
|
|
||||||
const USER_PERMISSIONS: Permission[] = [
|
const USER_PERMISSIONS: Permission[] = [
|
||||||
"users:read",
|
"users:read",
|
||||||
"ranks:read",
|
"ranks:read",
|
||||||
|
|
@ -47,34 +58,38 @@ const USER_PERMISSIONS: Permission[] = [
|
||||||
];
|
];
|
||||||
|
|
||||||
const ADMIN_PERMISSIONS: Permission[] = [
|
const ADMIN_PERMISSIONS: Permission[] = [
|
||||||
...USER_PERMISSIONS,
|
...new Set<Permission>([
|
||||||
"system:admin-access",
|
...USER_PERMISSIONS,
|
||||||
"users:read",
|
"system:admin-access",
|
||||||
"users:update",
|
"users:read",
|
||||||
"users:delete",
|
"users:update",
|
||||||
"technologies:create",
|
"users:delete",
|
||||||
"technologies:read",
|
"technologies:create",
|
||||||
"technologies:update",
|
"technologies:read",
|
||||||
"technologies:delete",
|
"technologies:update",
|
||||||
"tickets:read",
|
"technologies:delete",
|
||||||
"tickets:update",
|
"tickets:read",
|
||||||
"tickets:staff",
|
"tickets:update",
|
||||||
"bank-accounts:create",
|
"tickets:staff",
|
||||||
"bank-accounts:update",
|
"bank-accounts:create",
|
||||||
"user-notifications:read",
|
"bank-accounts:update",
|
||||||
"user-notifications:update",
|
"user-notifications:read",
|
||||||
"mission-attendances:create",
|
"user-notifications:update",
|
||||||
"mission-attendances:read",
|
"mission-attendances:create",
|
||||||
"mission-attendances:update",
|
"mission-attendances:read",
|
||||||
"mission-attendances:delete",
|
"mission-attendances:update",
|
||||||
"missions:read",
|
"mission-attendances:delete",
|
||||||
"market-negotiations:read",
|
"missions:read",
|
||||||
"market-negotiations:update",
|
"market-negotiations:read",
|
||||||
"logistics:manage",
|
"market-negotiations:update",
|
||||||
"banking:manage",
|
"logistics:manage",
|
||||||
"discord:staff",
|
"banking:manage",
|
||||||
"discord:announce",
|
"discord:staff",
|
||||||
"structures:create",
|
"discord:announce",
|
||||||
|
"structures:create",
|
||||||
|
...ALL_COLLECTION_READS,
|
||||||
|
...ALL_ADMIN_PAGE_MANAGE,
|
||||||
|
]),
|
||||||
];
|
];
|
||||||
|
|
||||||
interface BuiltinRole {
|
interface BuiltinRole {
|
||||||
|
|
@ -145,9 +160,36 @@ export const seedRoles = async () => {
|
||||||
});
|
});
|
||||||
|
|
||||||
if (existing.docs.length > 0) {
|
if (existing.docs.length > 0) {
|
||||||
const doc = existing.docs[0] as { id: number };
|
const doc = existing.docs[0] as {
|
||||||
|
id: number;
|
||||||
|
isSystem?: boolean;
|
||||||
|
permissions?: Permission[] | null;
|
||||||
|
};
|
||||||
roleIdMap.set(role.slug, doc.id);
|
roleIdMap.set(role.slug, doc.id);
|
||||||
payload.logger.info(` Role "${role.slug}" already exists (id=${doc.id}), skipping.`);
|
|
||||||
|
if (role.isSystem) {
|
||||||
|
const existingPerms = doc.permissions ?? [];
|
||||||
|
const missing = role.permissions.filter((p) => !existingPerms.includes(p));
|
||||||
|
if (missing.length > 0) {
|
||||||
|
await payload.update({
|
||||||
|
collection: "roles",
|
||||||
|
id: doc.id,
|
||||||
|
data: { permissions: [...existingPerms, ...missing] },
|
||||||
|
overrideAccess: true,
|
||||||
|
});
|
||||||
|
payload.logger.info(
|
||||||
|
` Role "${role.slug}" (id=${doc.id}) updated with ${missing.length} missing built-in permission(s).`,
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
payload.logger.info(
|
||||||
|
` Role "${role.slug}" already exists (id=${doc.id}), permissions up to date.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
payload.logger.info(
|
||||||
|
` Role "${role.slug}" already exists (id=${doc.id}), skipping (non-system).`,
|
||||||
|
);
|
||||||
|
}
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue