1
0
Fork 0
Commit graph

17 commits

Author SHA1 Message Date
0617794da7 fix(access): reserve approval final states for the superuser tier, gate admin panel entry on page permissions 2026-09-22 14:50:40 -04:00
4dde790aa8 feat(access): division-scoped admin page access
- scopedAdminPageAccess replaces requireAdminPageAccess: technologies pass for
  intelligence division members, assets/resources/vehicles for logistics;
  everyone else still needs admin:<slug>:manage
- technology approval is stripped from create/update below admin so division
  members can never self-approve; technologies access moves to the
  intelligence permission
- assets/resources/vehicles move to logistics division permissions
2026-09-21 20:48:08 -04:00
ad2fbb167a refactor(nav): sidebar minigames group, inline admin link, hidden map entry
Move minigame links from the user dropdown into a NavMinigames sidebar group, inline the admin link in AppSidebar via a new canAccessAdminPanel helper, guard NavCore against empty groups, drop the feedback secondary link, and add an empty navMap slot with a restore comment so the World Map ships hidden while /map stays live.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-09-16 23:14:16 -04:00
8d92e7aaa9 feat(promotions): add rank promotion ceiling with GM promote flow
Promotion service lib, ceiling field on Ranks, permission gate, migration, and GM promote button with tests.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-09-14 15:37:05 -04:00
f90d9348e7 fix(intel): require write permissions for wiki moderation qualification
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-09-11 03:25:59 -04:00
822ac47c23 feat(auth): scope Payload admin pages by permissions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@siisyphuslabs.ai>
2026-09-01 21:39:09 -04:00
0771424446 feat(campaigns): let members create and own campaigns 2026-08-26 00:53:17 -04:00
d6b2ffa5d2 chore(access-control): scaffold empty isAuthor helper stub 2026-08-25 13:27:48 -04:00
c0d00fc113 fix(auth): reject MCP API-key sessions in user auth paths
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
2026-08-25 12:27:35 -04:00
432929cc29 feat(awards): finish award profile presentation 2026-08-21 15:40:33 -04:00
eef1b11bb1 feat(rbac): migrate server actions and service layers to RBAC
Replace hasRoles calls with hasPermission in all server actions and page
components. Update qualification checks (logistics, intelligence) to use
permission-based checks instead of role name matching. Update staff lookup
in tickets/staff.ts to query roles collection. Use enlistmentDate field
on profile page instead of createdAt.
2026-08-19 19:47:57 -04:00
80f28ed939 feat(rbac): add dynamic roles collection and permissions system
Introduce a dynamic RBAC system with a new 'roles' collection that grants
granular permissions. Add hasPermission/requirePermission/loadUserPermissions
utilities and a central permissions registry. Register the Roles collection in
payload.config and add roleDocs relationship to Users.
2026-08-19 19:47:36 -04:00
6685fe68cd style(lib): format shared libraries and remove unused imports 2026-08-16 23:27:51 -04:00
caae76e6b2 feat(intelligence): gate intelligence content behind the intelligence qualification
- Add hasIntelligenceQualification access helper
- Redirect non-qualified users away from /intelligence
- Hide mission and campaign widgets on the dashboard for non-qualified users
- Guard hasLogisticsQualification against a null user
2026-08-11 23:25:27 -04:00
5ee98d61da feat(users): add trusted role, preferences, and profile/account auto-provisioning
- Add trusted role and isTrusted access helper
- Add notification muting and display preferences to the user schema
- Auto-create a profile and personal bank account when a user signs up
- Add idempotent backfillProfiles seed script for existing members
2026-08-11 23:25:09 -04:00
d3afc6a0c1 feat(realtime): add game-tick SSE notification pipeline 2026-08-02 02:03:56 -04:00
Z8MB1E
4d639387f4 feat: initial payload scaffolding 2025-10-24 02:07:13 -04:00