implemented permission system

This commit is contained in:
Alex
2025-03-02 10:27:56 +01:00
parent 298ef9843e
commit 29f405385e
6 changed files with 311 additions and 167 deletions

View File

@@ -5,6 +5,8 @@
import { page } from '$app/stores'; import { page } from '$app/stores';
import { t } from 'svelte-i18n'; import { t } from 'svelte-i18n';
import { writable } from 'svelte/store'; import { writable } from 'svelte/store';
import { PERMISSIONS } from '$lib/utils/constants';
import { hasPrivilige } from '$lib/utils/helpers';
let isMobileMenuOpen = false; let isMobileMenuOpen = false;
@@ -104,7 +106,7 @@
{$page.data.user.last_name} {$page.data.user.last_name}
</a> </a>
</div> </div>
{#if $page.data.user.role_id > 0} {#if hasPrivilige($page.data.user, PERMISSIONS.View)}
<div <div
class="header-nav-item" class="header-nav-item"
class:active={$page.url.pathname.startsWith(`${base}/auth/admin/users`)} class:active={$page.url.pathname.startsWith(`${base}/auth/admin/users`)}

View File

@@ -3,8 +3,9 @@
import SmallLoader from '$lib/components/SmallLoader.svelte'; import SmallLoader from '$lib/components/SmallLoader.svelte';
import { createEventDispatcher } from 'svelte'; import { createEventDispatcher } from 'svelte';
import { applyAction, enhance } from '$app/forms'; import { applyAction, enhance } from '$app/forms';
import { receive, send } from '$lib/utils/helpers'; import { hasPrivilige, receive, send } from '$lib/utils/helpers';
import { t } from 'svelte-i18n'; import { t } from 'svelte-i18n';
import { PERMISSIONS } from '$lib/utils/constants';
/** @type {import('../../routes/auth/about/[id]/$types').ActionData} */ /** @type {import('../../routes/auth/about/[id]/$types').ActionData} */
export let form; export let form;
@@ -29,7 +30,7 @@
profile_picture: '', profile_picture: '',
payment_status: 0, payment_status: 0,
status: 1, status: 1,
role_id: 0, role_id: 1,
membership: { membership: {
id: 0, id: 0,
start_date: '', start_date: '',
@@ -70,12 +71,14 @@
/** @type {App.Locals['user'] | null} */ /** @type {App.Locals['user'] | null} */
export let user; export let user;
/** @type {Number} */ /** @type {App.Locals['user']} */
export let role_id; export let editor;
/** @type {App.Locals['user'] } */ /** @type {App.Locals['user'] } */
let localUser; let localUser;
let readonlyUser = !hasPrivilige(editor, PERMISSIONS.Update);
$: { $: {
if (user !== undefined && !localUser) { if (user !== undefined && !localUser) {
localUser = localUser =
@@ -106,8 +109,9 @@
const userRoleOptions = [ const userRoleOptions = [
{ value: 0, label: $t('userRole.0'), color: '--subtext1' }, // Grey for "Nicht verifiziert" { value: 0, label: $t('userRole.0'), color: '--subtext1' }, // Grey for "Nicht verifiziert"
{ value: 1, label: $t('userRole.1'), color: '--light-green' }, // Light green for "Verifiziert" { value: 1, label: $t('userRole.1'), color: '--light-green' }, // Light green for "Verifiziert"
{ value: 4, label: $t('userRole.4'), color: '--green' }, // Green for "Aktiv" { value: 2, label: $t('userRole.2'), color: '--green' }, // Light green for "Verifiziert"
{ value: 8, label: $t('userRole.8'), color: '--pink' } // Pink for "Passiv" { value: 4, label: $t('userRole.4'), color: '--pink' }, // Green for "Aktiv"
{ value: 8, label: $t('userRole.8'), color: '--red' } // Pink for "Passiv"
]; ];
const membershipStatusOptions = [ const membershipStatusOptions = [
{ value: 3, label: $t('userStatus.3'), color: '--green' }, // Green for "Aktiv" { value: 3, label: $t('userStatus.3'), color: '--green' }, // Green for "Aktiv"
@@ -232,9 +236,9 @@
label={$t('status')} label={$t('status')}
bind:value={localUser.status} bind:value={localUser.status}
options={userStatusOptions} options={userStatusOptions}
readonly={role_id === 0} readonly={readonlyUser}
/> />
{#if role_id === 8} {#if hasPrivilige(editor, PERMISSIONS.Super)}
<InputField <InputField
name="user[role_id]" name="user[role_id]"
type="select" type="select"
@@ -243,6 +247,7 @@
options={userRoleOptions} options={userRoleOptions}
/> />
{/if} {/if}
{#if hasPrivilige(localUser, PERMISSIONS.Member)}
<InputField <InputField
name="user[password]" name="user[password]"
type="password" type="password"
@@ -259,13 +264,14 @@
bind:value={confirm_password} bind:value={confirm_password}
otherPasswordValue={password} otherPasswordValue={password}
/> />
{/if}
<InputField <InputField
name="user[first_name]" name="user[first_name]"
label={$t('user.first_name')} label={$t('user.first_name')}
bind:value={localUser.first_name} bind:value={localUser.first_name}
placeholder={$t('placeholder.first_name')} placeholder={$t('placeholder.first_name')}
required={true} required={true}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[last_name]" name="user[last_name]"
@@ -273,7 +279,7 @@
bind:value={localUser.last_name} bind:value={localUser.last_name}
placeholder={$t('placeholder.last_name')} placeholder={$t('placeholder.last_name')}
required={true} required={true}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[company]" name="user[company]"
@@ -296,14 +302,16 @@
bind:value={localUser.phone} bind:value={localUser.phone}
placeholder={$t('placeholder.phone')} placeholder={$t('placeholder.phone')}
/> />
{#if hasPrivilige(localUser, PERMISSIONS.Member)}
<InputField <InputField
name="user[dateofbirth]" name="user[dateofbirth]"
type="date" type="date"
label={$t('user.dateofbirth')} label={$t('user.dateofbirth')}
bind:value={localUser.dateofbirth} bind:value={localUser.dateofbirth}
placeholder={$t('placeholder.dateofbirth')} placeholder={$t('placeholder.dateofbirth')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
{/if}
<InputField <InputField
name="user[address]" name="user[address]"
label={$t('address')} label={$t('address')}
@@ -322,7 +330,7 @@
bind:value={localUser.city} bind:value={localUser.city}
placeholder={$t('placeholder.city')} placeholder={$t('placeholder.city')}
/> />
{#if role_id > 0} {#if !readonlyUser}
<InputField <InputField
name="user[notes]" name="user[notes]"
type="textarea" type="textarea"
@@ -335,6 +343,8 @@
/> />
{/if} {/if}
</div> </div>
{#if hasPrivilige(localUser, PERMISSIONS.Member)}
<div class="tab-content" style="display: {activeTab === 'licence' ? 'block' : 'none'}"> <div class="tab-content" style="display: {activeTab === 'licence' ? 'block' : 'none'}">
<InputField <InputField
name="user[licence][status]" name="user[licence][status]"
@@ -342,7 +352,7 @@
label={$t('status')} label={$t('status')}
bind:value={localUser.licence.status} bind:value={localUser.licence.status}
options={licenceStatusOptions} options={licenceStatusOptions}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[licence][number]" name="user[licence][number]"
@@ -351,7 +361,7 @@
bind:value={localUser.licence.number} bind:value={localUser.licence.number}
placeholder={$t('placeholder.licence_number')} placeholder={$t('placeholder.licence_number')}
toUpperCase={true} toUpperCase={true}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[licence][issued_date]" name="user[licence][issued_date]"
@@ -359,7 +369,7 @@
label={$t('issued_date')} label={$t('issued_date')}
bind:value={localUser.licence.issued_date} bind:value={localUser.licence.issued_date}
placeholder={$t('placeholder.issued_date')} placeholder={$t('placeholder.issued_date')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[licence][expiration_date]" name="user[licence][expiration_date]"
@@ -367,14 +377,14 @@
label={$t('expiration_date')} label={$t('expiration_date')}
bind:value={localUser.licence.expiration_date} bind:value={localUser.licence.expiration_date}
placeholder={$t('placeholder.expiration_date')} placeholder={$t('placeholder.expiration_date')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[licence][country]" name="user[licence][country]"
label={$t('country')} label={$t('country')}
bind:value={localUser.licence.country} bind:value={localUser.licence.country}
placeholder={$t('placeholder.issuing_country')} placeholder={$t('placeholder.issuing_country')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<div class="licence-categories"> <div class="licence-categories">
<h3>{$t('licence_categories')}</h3> <h3>{$t('licence_categories')}</h3>
@@ -406,6 +416,7 @@
</div> </div>
</div> </div>
</div> </div>
{/if}
<div class="tab-content" style="display: {activeTab === 'membership' ? 'block' : 'none'}"> <div class="tab-content" style="display: {activeTab === 'membership' ? 'block' : 'none'}">
<InputField <InputField
name="user[membership][status]" name="user[membership][status]"
@@ -413,7 +424,7 @@
label={$t('status')} label={$t('status')}
bind:value={localUser.membership.status} bind:value={localUser.membership.status}
options={membershipStatusOptions} options={membershipStatusOptions}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[membership][subscription_model][name]" name="user[membership][subscription_model][name]"
@@ -421,9 +432,10 @@
label={$t('subscription.subscription')} label={$t('subscription.subscription')}
bind:value={localUser.membership.subscription_model.name} bind:value={localUser.membership.subscription_model.name}
options={subscriptionModelOptions} options={subscriptionModelOptions}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<div class="subscription-info"> <div class="subscription-info">
{#if hasPrivilige(editor, PERMISSIONS.Member)}
<div class="subscription-column"> <div class="subscription-column">
<p> <p>
<strong>{$t('subscription.monthly_fee')}:</strong> <strong>{$t('subscription.monthly_fee')}:</strong>
@@ -446,6 +458,7 @@
</p> </p>
{/if} {/if}
</div> </div>
{/if}
<div class="subscription-column"> <div class="subscription-column">
<p> <p>
<strong>{$t('details')}:</strong> <strong>{$t('details')}:</strong>
@@ -465,7 +478,7 @@
label={$t('start')} label={$t('start')}
bind:value={localUser.membership.start_date} bind:value={localUser.membership.start_date}
placeholder={$t('placeholder.start_date')} placeholder={$t('placeholder.start_date')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[membership][end_date]" name="user[membership][end_date]"
@@ -473,16 +486,18 @@
label={$t('end')} label={$t('end')}
bind:value={localUser.membership.end_date} bind:value={localUser.membership.end_date}
placeholder={$t('placeholder.end_date')} placeholder={$t('placeholder.end_date')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
{#if hasPrivilige(editor, PERMISSIONS.Member)}
<InputField <InputField
name="user[membership][parent_member_id]" name="user[membership][parent_member_id]"
type="number" type="number"
label={$t('parent_member_id')} label={$t('parent_member_id')}
bind:value={localUser.membership.parent_member_id} bind:value={localUser.membership.parent_member_id}
placeholder={$t('placeholder.parent_member_id')} placeholder={$t('placeholder.parent_member_id')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
{/if}
</div> </div>
<div class="tab-content" style="display: {activeTab === 'bankaccount' ? 'block' : 'none'}"> <div class="tab-content" style="display: {activeTab === 'bankaccount' ? 'block' : 'none'}">
<InputField <InputField
@@ -516,7 +531,7 @@
label={$t('mandate_reference')} label={$t('mandate_reference')}
bind:value={localUser.bank_account.mandate_reference} bind:value={localUser.bank_account.mandate_reference}
placeholder={$t('placeholder.mandate_reference')} placeholder={$t('placeholder.mandate_reference')}
readonly={role_id === 0} readonly={readonlyUser}
/> />
<InputField <InputField
name="user[bank_account][mandate_date_signed]" name="user[bank_account][mandate_date_signed]"

View File

@@ -36,7 +36,7 @@
default: 'unknown status' default: 'unknown status'
})}</span })}</span
> >
<span>{$t(`userRole.${user.role_id}`, { default: 'unknown role' })}</span> <span>{$t(`userRole.${user.role_id}`, { default: 'unknown' })}</span>
</span> </span>
</h3> </h3>
{/if} {/if}
@@ -93,7 +93,7 @@
{licence_categories} {licence_categories}
on:close={close} on:close={close}
on:cancel={close} on:cancel={close}
role_id={user.role_id} editor={user}
/> />
</Modal> </Modal>
{/if} {/if}

View File

@@ -2,8 +2,8 @@
// - Implement a load function to fetch a list of all users. // - Implement a load function to fetch a list of all users.
// - Create actions for updating user information (similar to the about/[id] route). // - Create actions for updating user information (similar to the about/[id] route).
import { BASE_API_URI } from '$lib/utils/constants'; import { BASE_API_URI, PERMISSIONS } from '$lib/utils/constants';
import { formatError, userDatesFromRFC3339 } from '$lib/utils/helpers'; import { formatError, hasPrivilige, userDatesFromRFC3339 } from '$lib/utils/helpers';
import { fail, redirect } from '@sveltejs/kit'; import { fail, redirect } from '@sveltejs/kit';
import { import {
formDataToObject, formDataToObject,
@@ -18,7 +18,7 @@ export async function load({ locals }) {
if (!locals.user) { if (!locals.user) {
throw redirect(302, `${base}/auth/login?next=${base}/auth/admin/users`); throw redirect(302, `${base}/auth/login?next=${base}/auth/admin/users`);
} }
if (locals.user.role_id === 0) { if (!hasPrivilige(locals.user, PERMISSIONS.View)) {
throw redirect(302, `${base}/auth/about/${locals.user.id}`); throw redirect(302, `${base}/auth/about/${locals.user.id}`);
} }
} }

View File

@@ -6,7 +6,8 @@
import { t } from 'svelte-i18n'; import { t } from 'svelte-i18n';
import { page } from '$app/stores'; import { page } from '$app/stores';
import { applyAction, enhance } from '$app/forms'; import { applyAction, enhance } from '$app/forms';
import { receive, send } from '$lib/utils/helpers'; import { hasPrivilige, receive, send } from '$lib/utils/helpers';
import { PERMISSIONS } from '$lib/utils/constants';
/** @type {import('./$types').ActionData} */ /** @type {import('./$types').ActionData} */
export let form; export let form;
@@ -19,7 +20,7 @@
payments = [] payments = []
} = $page.data); } = $page.data);
let activeSection = 'users'; let activeSection = 'members';
/** @type{App.Locals['user'] | null} */ /** @type{App.Locals['user'] | null} */
let selectedUser = null; let selectedUser = null;
/** @type{App.Types['subscription'] | null} */ /** @type{App.Types['subscription'] | null} */
@@ -28,9 +29,21 @@
let showUserModal = false; let showUserModal = false;
let searchTerm = ''; let searchTerm = '';
$: filteredUsers = searchTerm ? getFilteredUsers() : users; $: members = users.filter((/** @type{App.Locals['user']} */ user) => {
return user.role_id >= PERMISSIONS.Member;
});
$: supporters = users.filter((/** @type{App.Locals['user']} */ user) => {
return user.role_id < PERMISSIONS.Member;
});
$: filteredMembers = searchTerm ? getFilteredUsers(members) : members;
function handleMailButtonClick() { $: filteredSupporters = searchTerm ? getFilteredUsers(supporters) : supporters;
/**
* Handles Mail button click to open a formatted mailto link
* @param {App.Locals['user'][]} filteredUsers - the users to send the mail to
*/
function handleMailButtonClick(filteredUsers) {
const subject = 'Important Announcement'; const subject = 'Important Announcement';
const body = `Hello everyone,\n\nThis is an important message.`; const body = `Hello everyone,\n\nThis is an important message.`;
const bccEmails = filteredUsers const bccEmails = filteredUsers
@@ -43,14 +56,15 @@
} }
/** /**
* returns a set of users depending on the entered search query * returns a set of members depending on the entered search query
* @param {App.Locals['user'][]} userSet Set to filter
* @return {App.Locals['user'][]}*/ * @return {App.Locals['user'][]}*/
const getFilteredUsers = () => { const getFilteredUsers = (userSet) => {
if (!searchTerm.trim()) return users; if (!searchTerm.trim()) return userSet;
const term = searchTerm.trim().toLowerCase(); const term = searchTerm.trim().toLowerCase();
return users.filter((/** @type{App.Locals['user']}*/ user) => { return userSet.filter((/** @type{App.Locals['user']}*/ user) => {
const basicMatch = [ const basicMatch = [
user.first_name?.toLowerCase(), user.first_name?.toLowerCase(),
user.last_name?.toLowerCase(), user.last_name?.toLowerCase(),
@@ -124,12 +138,22 @@
<ul class="nav-list"> <ul class="nav-list">
<li> <li>
<button <button
class="nav-link {activeSection === 'users' ? 'active' : ''}" class="nav-link {activeSection === 'members' ? 'active' : ''}"
on:click={() => setActiveSection('users')} on:click={() => setActiveSection('members')}
> >
<i class="fas fa-users"></i> <i class="fas fa-users"></i>
{$t('users')} {$t('users')}
<span class="nav-badge">{users.length}</span> <span class="nav-badge">{members.length}</span>
</button>
</li>
<li>
<button
class="nav-link {activeSection === 'supporter' ? 'active' : ''}"
on:click={() => setActiveSection('supporter')}
>
<i class="fas fa-hand-holding-dollar"></i>
{$t('supporter')}
<span class="nav-badge">{supporters.length}</span>
</button> </button>
</li> </li>
<li> <li>
@@ -168,7 +192,7 @@
{/each} {/each}
{/if} {/if}
{#if activeSection === 'users'} {#if activeSection === 'members'}
<div class="section-header"> <div class="section-header">
<h2>{$t('users')}</h2> <h2>{$t('users')}</h2>
<div class="title-container"> <div class="title-container">
@@ -183,7 +207,7 @@
<button <button
class="btn primary" class="btn primary"
aria-label="Mail Users" aria-label="Mail Users"
on:click={() => handleMailButtonClick()} on:click={() => handleMailButtonClick(filteredMembers)}
> >
<i class="fas fa-envelope"></i> <i class="fas fa-envelope"></i>
</button> </button>
@@ -196,7 +220,108 @@
</div> </div>
</div> </div>
<div class="accordion"> <div class="accordion">
{#each filteredUsers as user} {#each filteredMembers as user}
<details class="accordion-item">
<summary class="accordion-header">
{user.first_name}
{user.last_name}
</summary>
<div class="accordion-content">
<table class="table">
<tbody>
<tr>
<th>{$t('user.id')}</th>
<td>{user.id}</td>
</tr>
<tr>
<th>{$t('name')}</th>
<td>{user.first_name} {user.last_name}</td>
</tr>
<tr>
<th>{$t('user.email')}</th>
<td>{user.email}</td>
</tr>
<tr>
<th>{$t('subscription.subscription')}</th>
<td>{user.membership?.subscription_model?.name}</td>
</tr>
<tr>
<th>{$t('status')}</th>
<td>{$t('userStatus.' + user.status)}</td>
</tr>
</tbody>
</table>
<div class="button-group">
<button class="btn primary" on:click={() => openEditUserModal(user)}>
<i class="fas fa-edit"></i>
{$t('edit')}
</button>
<form
method="POST"
action="?/userDelete"
use:enhance={() => {
return async ({ result }) => {
if (result.type === 'success' || result.type === 'redirect') {
await applyAction(result);
}
};
}}
on:submit|preventDefault={(/** @type {SubmitEvent} */ e) => {
if (
!confirm(
$t('dialog.user_deletion', {
values: {
firstname: user.first_name || '',
lastname: user.last_name || ''
}
})
)
) {
e.preventDefault(); // Cancel form submission if user declines
}
}}
>
<input type="hidden" name="user[id]" value={user.id} />
<input type="hidden" name="user[last_name]" value={user.last_name} />
<button class="btn danger" type="submit">
<i class="fas fa-trash"></i>
{$t('delete')}
</button>
</form>
</div>
</div>
</details>
{/each}
</div>
{:else if activeSection === 'supporter'}
<div class="section-header">
<h2>{$t('supporter')}</h2>
<div class="title-container">
<InputField
name="search"
bind:value={searchTerm}
placeholder={$t('placeholder.search')}
backgroundColor="--base"
/>
</div>
<div>
<button
class="btn primary"
aria-label="Mail Supporter"
on:click={() => handleMailButtonClick(filteredSupporters)}
>
<i class="fas fa-envelope"></i>
</button>
</div>
<div>
<button class="btn primary" on:click={() => openEditUserModal(null)}>
<i class="fas fa-plus"></i>
{$t('add_new')}
</button>
</div>
</div>
<div class="accordion">
{#each filteredSupporters as user}
<details class="accordion-item"> <details class="accordion-item">
<summary class="accordion-header"> <summary class="accordion-header">
{user.first_name} {user.first_name}
@@ -272,7 +397,7 @@
{:else if activeSection === 'subscriptions'} {:else if activeSection === 'subscriptions'}
<div class="section-header"> <div class="section-header">
<h2>{$t('subscription.subscriptions')}</h2> <h2>{$t('subscription.subscriptions')}</h2>
{#if user.role_id == 8} {#if hasPrivilige(user, PERMISSIONS.Super)}
<button class="btn primary" on:click={() => openEditSubscriptionModal(null)}> <button class="btn primary" on:click={() => openEditSubscriptionModal(null)}>
<i class="fas fa-plus"></i> <i class="fas fa-plus"></i>
{$t('add_new')} {$t('add_new')}
@@ -285,7 +410,7 @@
<summary class="accordion-header"> <summary class="accordion-header">
{subscription.name} {subscription.name}
<span class="nav-badge" <span class="nav-badge"
>{users.filter( >{members.filter(
(/** @type{App.Locals['user']}*/ user) => (/** @type{App.Locals['user']}*/ user) =>
user.membership?.subscription_model?.name === subscription.name user.membership?.subscription_model?.name === subscription.name
).length}</span ).length}</span
@@ -328,7 +453,7 @@
</tr> </tr>
</tbody> </tbody>
</table> </table>
{#if user.role_id == 8} {#if hasPrivilige(user, PERMISSIONS.Super)}
<div class="button-group"> <div class="button-group">
<button <button
class="btn primary" class="btn primary"
@@ -337,7 +462,7 @@
<i class="fas fa-edit"></i> <i class="fas fa-edit"></i>
{$t('edit')} {$t('edit')}
</button> </button>
{#if !users.some(/** @param{App.Locals['user']} user */ (user) => user.membership?.subscription_model?.id === subscription.id)} {#if !members.some(/** @param{App.Locals['user']} user */ (user) => user.membership?.subscription_model?.id === subscription.id)}
<form <form
method="POST" method="POST"
action="?/subscriptionDelete" action="?/subscriptionDelete"
@@ -415,7 +540,7 @@
<Modal on:close={close}> <Modal on:close={close}>
<UserEditForm <UserEditForm
{form} {form}
role_id={user.role_id} editor={user}
user={selectedUser} user={selectedUser}
{subscriptions} {subscriptions}
{licence_categories} {licence_categories}

View File

@@ -66,20 +66,22 @@ var Priviliges = struct {
Update int8 Update int8
Delete int8 Delete int8
}{ }{
View: 1, View: 2,
Update: 4, Update: 4,
Create: 4, Create: 4,
Delete: 4, Delete: 4,
} }
var Roles = struct { var Roles = struct {
Supporter int8
Member int8 Member int8
Viewer int8 Viewer int8
Editor int8 Editor int8
Admin int8 Admin int8
}{ }{
Member: 0, Supporter: 0,
Viewer: 1, Member: 1,
Viewer: 2,
Editor: 4, Editor: 4,
Admin: 8, Admin: 8,
} }