docs: document the intelligence visibility access layer
This commit is contained in:
parent
ef7295c0d4
commit
d08ea8929c
1 changed files with 4 additions and 1 deletions
|
|
@ -26,7 +26,10 @@ Full RBAC check against `src/permissions/index.ts` (100+ permissions). Superuser
|
|||
Lightweight role checks. Used for quick conditional rendering (e.g., `isRole("admin")` for admin-only UI). No Payload call — reads from the user object directly.
|
||||
|
||||
### 3. `hasLogisticsQualification()` / `hasIntelligenceQualification()`
|
||||
Queries `Profiles.progression.qualifications` for specific qualification strings (case-insensitive). Admin/developer always pass. Used to gate logistics-only and intelligence-only UI sections.
|
||||
Queries `Profiles.progression.qualifications` for specific qualification strings (case-insensitive), with domain write permissions as a pass. Admin/developer always pass. Used to gate moderation and management surfaces (wiki moderation, tech tree editing, division admin pages, logistics-only UI).
|
||||
|
||||
### 4. `canViewIntelligence()`
|
||||
Read-permission visibility check (`missions:read` / `campaigns:read` / `factions:read` / `technologies:read`, all granted by the standard user role) with the strict intelligence qualification as fallback. Gates the Intelligence sidebar section, command palette, keyboard shortcuts, dashboard widgets, and tour visibility. Never use it for moderation decisions; use `hasIntelligenceQualification()` for those.
|
||||
|
||||
### Permission tiers and admin panel gates
|
||||
- `system:admin-access` (registry label "Superuser Tier (user management, notification oversight, final approval states)") is the functional superuser tier: final approval states (`approvalStatusFieldAccess` in `divisionAccess.ts`), the Users admin page, read-all notifications. Held ONLY by the built-in `admin` role and superuser roles. NEVER grant it to division roles; a hand grant once made officers approval-superusers.
|
||||
|
|
|
|||
Loading…
Reference in a new issue