Initial commit of Descrybe v2 without local scratch artifacts.
Drop one-shot tmp/axe scripts and agent i18n scratch so the Gitea tree is deployable.
This commit is contained in:
@@ -0,0 +1,92 @@
|
||||
package auth
|
||||
|
||||
import (
|
||||
"strings"
|
||||
)
|
||||
|
||||
// StaffRoleFromPlatformAdmin maps the legacy boolean gate onto staff roles.
|
||||
// Until a dedicated staff_role column exists: platform admin → admin.
|
||||
func StaffRoleFromPlatformAdmin(isPlatformAdmin bool) string {
|
||||
if isPlatformAdmin {
|
||||
return StaffRoleAdmin
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// supportStaffFeatureOff keys denied for support_staff (03-roles-matrix.json).
|
||||
var supportStaffFeatureOff = map[string]struct{}{
|
||||
"billing.checkout": {},
|
||||
"billing.customer_portal": {},
|
||||
"billing.quick_upgrade": {},
|
||||
"capability.api_access": {},
|
||||
"capability.brand_ai_apply": {},
|
||||
"capability.byok": {},
|
||||
"capability.campaign_ai": {},
|
||||
"capability.email_live_send": {},
|
||||
"capability.seo_ai_rewrite": {},
|
||||
"catalog.structured_descriptions": {},
|
||||
"catalog.vector_categories": {},
|
||||
"dashboard.store_reconnect": {},
|
||||
"integrations.ai": {},
|
||||
"integrations.ai.byok": {},
|
||||
"integrations.email": {},
|
||||
"integrations.email.blast": {},
|
||||
"integrations.email.test": {},
|
||||
"marketing.brand_ai_apply": {},
|
||||
"marketing.brand_kit": {},
|
||||
"marketing.campaigns": {},
|
||||
"marketing.campaigns.create": {},
|
||||
"marketing.campaigns.generate_ai": {},
|
||||
"marketing.campaigns.send": {},
|
||||
"marketing.content_calendar": {},
|
||||
"marketing.reviews": {},
|
||||
"marketing.seo": {},
|
||||
"marketing.seo.ai_rewrite": {},
|
||||
"marketing.seo.template_fill": {},
|
||||
"settings.api_keys": {},
|
||||
"settings.team_invite": {},
|
||||
"stores.hub": {},
|
||||
"stores.shopify": {},
|
||||
"stores.shopify.connection": {},
|
||||
"stores.shopify.orders": {},
|
||||
"stores.shopify.settings": {},
|
||||
"stores.woocommerce": {},
|
||||
"stores.woocommerce.attributes": {},
|
||||
"stores.woocommerce.categories": {},
|
||||
"stores.woocommerce.connection": {},
|
||||
"stores.woocommerce.orders": {},
|
||||
"stores.woocommerce.reviews": {},
|
||||
"stores.woocommerce.settings": {},
|
||||
}
|
||||
|
||||
// DefaultStaffRoleAllows reports the dashboard feature ceiling for a staff role
|
||||
// when acting in a tenant context (compose with plan_allows at resolve time).
|
||||
// admin / developer → all keys ON; support_staff → limited set; unknown → false.
|
||||
func DefaultStaffRoleAllows(role string, featureKey string) bool {
|
||||
featureKey = strings.TrimSpace(featureKey)
|
||||
normalized, _ := NormalizeStaffRole(role)
|
||||
switch normalized {
|
||||
case StaffRoleAdmin, StaffRoleDeveloper:
|
||||
return true
|
||||
case StaffRoleSupportStaff:
|
||||
_, denied := supportStaffFeatureOff[featureKey]
|
||||
return !denied
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
// StaffRoleAllowsAdminRoute is the platform console ceiling (not feature keys).
|
||||
// Per contract 04: support_staff → /admin/support only; admin|developer → all.
|
||||
func StaffRoleAllowsAdminRoute(role string, route string) bool {
|
||||
route = strings.ToLower(strings.TrimSpace(route))
|
||||
normalized, _ := NormalizeStaffRole(role)
|
||||
switch normalized {
|
||||
case StaffRoleAdmin, StaffRoleDeveloper:
|
||||
return true
|
||||
case StaffRoleSupportStaff:
|
||||
return strings.HasPrefix(route, "/admin/support")
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user