feat(rbac): no role at registration; invitation-based membership; nav gating
- Registration no longer asks for a role/persona (removed the role select + allottee block); crm.account.register sends no persona. - New users have no permissions → the sidebar now shows only Dashboard + Profile for them, gated on crm.account.me (membership + permissions). Members see the areas their permissions allow. - Add /portal/invite?token=… : accepts the invite for a signed-in registered user, or routes an unregistered invitee through register/onboarding, which redeems the stashed token on completion (granting the invited role). - Team Management: 'Copy link' on pending invites builds the invite link from the invitation token (no email delivery yet).
This commit is contained in:
@@ -6,6 +6,7 @@ import { ChevronsUpDown, LogOut } from "lucide-react";
|
||||
import { useAuth } from "@abe-kap/appshell-sdk/react";
|
||||
import { Icon } from "./ui";
|
||||
import { user } from "./account-data";
|
||||
import { useMyAccess } from "@/lib/access";
|
||||
|
||||
function initialsOf(name: string): string {
|
||||
return name.split(/\s+/).filter(Boolean).slice(0, 2).map((p) => p[0]).join("").toUpperCase() || "?";
|
||||
@@ -67,10 +68,45 @@ export const NAV_GROUPS: NavGroup[] = [
|
||||
|
||||
export const NAV_ITEMS: NavItem[] = NAV_GROUPS.flatMap((g) => g.items);
|
||||
|
||||
// Nav visibility by CRM permission. Dashboard + Profile are always visible (even to a
|
||||
// brand-new user with no membership); every other item requires membership, and the
|
||||
// items mapped here additionally require the given permission. Unmapped items are
|
||||
// shown to any member. This is UX only — be-crm still enforces every action.
|
||||
const ALWAYS_VISIBLE = new Set(["dashboard", "profile"]);
|
||||
const NAV_PERMISSION: Record<string, string | undefined> = {
|
||||
team: "team.manage",
|
||||
people: "team.manage",
|
||||
leads: "leads.manage",
|
||||
verify: "leads.manage",
|
||||
pipeline: "pipeline.manage",
|
||||
estimates: "estimates.create",
|
||||
procanvas: "estimates.create",
|
||||
dispatch: "dispatch.manage",
|
||||
schedule: "dispatch.manage",
|
||||
storm: "dispatch.manage",
|
||||
territory: "dispatch.manage",
|
||||
leaderboard: "reports.view",
|
||||
settings: "settings.manage",
|
||||
};
|
||||
|
||||
export function Sidebar({ active, onSelect }: { active: string; onSelect: (k: string) => void }) {
|
||||
const router = useRouter();
|
||||
const { user: me, logout, context } = useAuth();
|
||||
const access = useMyAccess();
|
||||
const [menuOpen, setMenuOpen] = useState(false);
|
||||
|
||||
// A new user with no membership sees only Dashboard + Profile. Members see the areas
|
||||
// their permissions allow. While access is still loading, keep it minimal to avoid
|
||||
// flashing items the user can't actually use.
|
||||
const canSee = (key: string): boolean => {
|
||||
if (ALWAYS_VISIBLE.has(key)) return true;
|
||||
if (access.loading || !access.isMember) return false;
|
||||
const perm = NAV_PERMISSION[key];
|
||||
return perm ? access.can(perm) : true;
|
||||
};
|
||||
const visibleGroups = NAV_GROUPS
|
||||
.map((g) => ({ ...g, items: g.items.filter((it) => canSee(it.key)) }))
|
||||
.filter((g) => g.items.length > 0);
|
||||
// Real signed-in identity from the App Context Envelope; fall back to the static
|
||||
// demo user only when the Shell isn't wired.
|
||||
const roleLabel = context?.scope?.role ? context.scope.role.charAt(0).toUpperCase() + context.scope.role.slice(1) : "";
|
||||
@@ -92,7 +128,7 @@ export function Sidebar({ active, onSelect }: { active: string; onSelect: (k: st
|
||||
</div>
|
||||
|
||||
<nav className="dash-nav">
|
||||
{NAV_GROUPS.map((g, gi) => (
|
||||
{visibleGroups.map((g, gi) => (
|
||||
<div className="nav-section" key={gi}>
|
||||
<div className="nav-group">{g.title}</div>
|
||||
{g.items.map((it) => (
|
||||
|
||||
Reference in New Issue
Block a user