fix(secretary): route «نوبت‌دهی» settings to the scope-correct variant

A clinic-scoped secretary opening «مدیریت نوبت دهی» hit 404s
(/api/v1/doctor/{clinicUuid}, available-locations, weekly-schedule): the
permission-only secretary filter ignored each item's `roles`, so BOTH
appointment-settings variants (doctor → /admin/appointment-settings,
clinic → /admin/settings/appointment-settings) showed. Clicking the doctor
variant landed on the personal page, which has no doctor uuid for a clinic
secretary and fell back to the clinic uuid — not a doctor → 404.

Make the secretary settings filter scope-aware in both navs
(PurchaseSubscriptionSidebar + menuForRole): a role-variant item is kept only
when its `roles` matches the secretary's context scope (clinic→'clinic',
else 'doctor'). The clinic page already threads clinic_uuid through
ScheduleSection, so once routed correctly the flow works end-to-end.

Test: appointment variant resolves to the clinic route under clinic scope.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
hamed
2026-07-23 18:11:41 +03:30
co-authored by Claude Opus 4.8
parent d986cff255
commit 221dce29c3
4 changed files with 35 additions and 9 deletions
@@ -46,11 +46,15 @@ export const SETTINGS_MENU: SettingsMenuItem[] = [
export function menuForRole(
role: string | null | undefined,
can?: (resource: string, action: string) => boolean,
scope?: string | null,
): SettingsMenuItem[] {
return SETTINGS_MENU.filter((i) => {
if (role === 'secretary') {
if (i.alwaysOpen) return true;
return i.perm && can ? can(i.perm[0], i.perm[1]) : false;
if (!i.perm || !can || !can(i.perm[0], i.perm[1])) return false;
// واریانتِ نقشی (نوبت‌دهی/پزشکان کلینیک) را با scope منشی تطبیق بده.
if (i.roles) return i.roles.includes(scope === 'clinic' ? 'clinic' : 'doctor');
return true;
}
return !i.roles || (role != null && i.roles.includes(role));
});