- scopedAdminPageAccess replaces requireAdminPageAccess: technologies pass for
intelligence division members, assets/resources/vehicles for logistics;
everyone else still needs admin:<slug>:manage
- technology approval is stripped from create/update below admin so division
members can never self-approve; technologies access moves to the
intelligence permission
- assets/resources/vehicles move to logistics division permissions
Consume raw arma-sync-events into a validated, idempotent operation ledger: contract v1, reject/dead-letter with zero effects, effect keys with unique-constraint race handling, and a staged-activation flag hook. Registers the operations permission domains.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Move minigame links from the user dropdown into a NavMinigames sidebar group, inline the admin link in AppSidebar via a new canAccessAdminPanel helper, guard NavCore against empty groups, drop the feedback secondary link, and add an empty navMap slot with a restore comment so the World Map ships hidden while /map stays live.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Promotion service lib, ceiling field on Ranks, permission gate, migration, and GM promote button with tests.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Additive event types (blackjack, personnel promotion, respawn tickets) and the promotion notification label consumed by the following feature commits.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Awards can now upgrade through a series: collection fields and migration, grant flow support, profile and account UI updates, and regression coverage.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Adds a 'Mark as Ready' control on the mission detail page (owner or missions:update gated) plus the markSideOpReady server action. Status-gated to Concept/Planning/Scheduled; emits a mission:ready event. Stops the daily ready-reminders and lets missionEmbeds post the roll-call.
Add VoiceScripts and VoiceSubmissions collections, voiceover event types and event-log targets, the voice-submissions migration, and a voiceover XP group on Profiles counted toward total XP.
Ultraworked with [Sisyphus](https://github.com/code-yeongju/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add the src/lib/economy service (GM baselines, deterministic per-period demand drift, price modifier computation, event emission) and the economy-tick bin. Gated by GameRules economy.enabled; period-idempotent with a cold-start observation gate.
Ultraworked with [Sisyphus](https://github.com/code-yeongju/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Update root and per-directory AGENTS.md files to reflect the current
state of the codebase: collection inventory, RBAC registry, base
management, personnel pages, training minigames, Discord bot transfer
and evaluation-reminder flows, banking currency config, migration
wrapper, and Playwright/Vivaldi e2e details.
Convert the dossier personal excerpt from a plain textarea to Lexical
rich text (matching the intel excerpt) with a 1000-character plain-text
limit, and replace the static read-only cards on the profile page with
inline DossierExcerptEditors: owners edit their personal excerpt,
profiles:intel_excerpt:update holders edit the intelligence record.
Changes are validated server-side (lexicalPlaintextLength) and emit
dossier:personal-excerpt-update / dossier:intel-excerpt-update events.
Adds staff:hired/terminated/headcount-set, staff:salary-paid/unpaid, structure:upgraded/maintenance-paid/maintenance-unpaid/upkeep-short event types and registers npc-staffing as an event target collection.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Server actions for page create/update, revision restore, lockdown, and
delete (moderator-gated via intelligence qualification) plus wiki image
uploads. Adds wiki event types (wiki:page-create/edit/restore/lock/
unlock/delete) and registers wiki-pages/revisions/templates as valid event
log targets.
Add event logging constants for assignment transfer events:
- AssignmentTransferRequest: Request initiated by user
- AssignmentTransferApprove: Leader approved transfer
- AssignmentTransferReject: Leader rejected transfer with reason
- AssignmentTransferAppeal: User appealed a rejection
- AssignmentTransferResolve: Final resolution by superuser
- AssignmentTransferComplete: Transfer completed successfully
- AssignmentTransferCancel: Transfer cancelled
Add assignment-transfers to GameEventLogs TARGET_COLLECTIONS
Add emitGameEvent support for all transfer event types in src/utils/event-log/emit.ts
This provides audit trail and notification support for the transfer workflow.
Mission objectives gain a redacted checkbox. Redacted objectives are
shown block-redacted to players; mission managers, authors, and Zeus
see the real text (via tooltip) and can toggle the flag from the
mission detail page. Toggles emit mission:objective-redacted-toggle
events. Also registers the mission:auto-complete event type used by
the upcoming mission-tick bin.
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
Add domain-specific AGENTS.md files for collections, components, lib,
utils, and bot. Add login-return-url case study documenting the
return-URL flow design decisions and debugging lessons learned.
Replace hasRoles calls with hasPermission in all server actions and page
components. Update qualification checks (logistics, intelligence) to use
permission-based checks instead of role name matching. Update staff lookup
in tickets/staff.ts to query roles collection. Use enlistmentDate field
on profile page instead of createdAt.
Introduce a dynamic RBAC system with a new 'roles' collection that grants
granular permissions. Add hasPermission/requirePermission/loadUserPermissions
utilities and a central permissions registry. Register the Roles collection in
payload.config and add roleDocs relationship to Users.
- Add hasIntelligenceQualification access helper
- Redirect non-qualified users away from /intelligence
- Hide mission and campaign widgets on the dashboard for non-qualified users
- Guard hasLogisticsQualification against a null user