- scopedAdminPageAccess replaces requireAdminPageAccess: technologies pass for
intelligence division members, assets/resources/vehicles for logistics;
everyone else still needs admin:<slug>:manage
- technology approval is stripped from create/update below admin so division
members can never self-approve; technologies access moves to the
intelligence permission
- assets/resources/vehicles move to logistics division permissions
Move minigame links from the user dropdown into a NavMinigames sidebar group, inline the admin link in AppSidebar via a new canAccessAdminPanel helper, guard NavCore against empty groups, drop the feedback secondary link, and add an empty navMap slot with a restore comment so the World Map ships hidden while /map stays live.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Promotion service lib, ceiling field on Ranks, permission gate, migration, and GM promote button with tests.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
Replace hasRoles calls with hasPermission in all server actions and page
components. Update qualification checks (logistics, intelligence) to use
permission-based checks instead of role name matching. Update staff lookup
in tickets/staff.ts to query roles collection. Use enlistmentDate field
on profile page instead of createdAt.
Introduce a dynamic RBAC system with a new 'roles' collection that grants
granular permissions. Add hasPermission/requirePermission/loadUserPermissions
utilities and a central permissions registry. Register the Roles collection in
payload.config and add roleDocs relationship to Users.
- Add hasIntelligenceQualification access helper
- Redirect non-qualified users away from /intelligence
- Hide mission and campaign widgets on the dashboard for non-qualified users
- Guard hasLogisticsQualification against a null user
- Add trusted role and isTrusted access helper
- Add notification muting and display preferences to the user schema
- Auto-create a profile and personal bank account when a user signs up
- Add idempotent backfillProfiles seed script for existing members