1
0
Fork 0
Commit graph

4 commits

Author SHA1 Message Date
c0d00fc113 fix(auth): reject MCP API-key sessions in user auth paths
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
2026-08-25 12:27:35 -04:00
eef1b11bb1 feat(rbac): migrate server actions and service layers to RBAC
Replace hasRoles calls with hasPermission in all server actions and page
components. Update qualification checks (logistics, intelligence) to use
permission-based checks instead of role name matching. Update staff lookup
in tickets/staff.ts to query roles collection. Use enlistmentDate field
on profile page instead of createdAt.
2026-08-19 19:47:57 -04:00
bc1456db88 feat(notify): push banking move and shipment arrival owner notifications 2026-08-12 12:38:46 -04:00
ee87bd3023 feat(banking): add banking server actions and event logging 2026-08-02 04:10:37 -04:00