feat(secretary): grant staff/discounts/sms/appointment_settings/clinic_doctors (phase B)
Extends the secretary permission system to five previously owner-only modules, so a clinic/doctor can delegate each page to a secretary. All were unreachable by secretaries before (role-based tenant resolution returned "unknown" → 403). New permission resources (default-deny, three-place add: entity default, SecretaryPermissions type, both MySecretariesPage + admin SecretariesPage): staff, discounts, sms, appointment_settings (view/update only), clinic_doctors (clinic-only — hidden from independent doctors via `clinicOnly` section filter). Backend enforcement (SecretaryAccessChecker, three new reusable helpers): - resolveOwnerEntity(): owner pair from active context — used by StaffController, DiscountController, SmsWalletController (now secretary-aware resolveEntity). - canForDoctor(): per-doctor-scoped check (assigned doctor + toggle) — wired into AppointmentSettingsController::denyDoctorAccess. - canForClinic(): clinic-scoped check — wired into ClinicController::detachDoctor, ClinicDoctorPermissionController (view/update), ClinicInvitationController (create/view/update/delete). clinic_doctors is clinic-context only. Guards run ahead of any subscription gate; non-secretary roles pass unchanged. Frontend: - RoleRoute: staff, discounts, sms-wallet, appointment-settings (doctor+clinic variants), settings/clinic-doctors routes accept secretary + permission gate. - Sidebar (secretary branch): five new items gated by can(); appointment_settings route follows active scope; clinic_doctors only in clinic scope. Tests: SecretaryResourceEnforcementTest — denied-by-default + allowed-when-granted for all five (18 total). Sidebar.test — B-resource gating + clinic_doctors scope rule. docs/api/secretary.md resource list, enforcement map, JSON example updated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -116,4 +116,43 @@ describe("Sidebar — گِیت منوی منشی بر اساس مجوز", () =>
|
||||
"/admin/tags-settings",
|
||||
);
|
||||
});
|
||||
|
||||
it("منابع فاز B (staff/discounts/sms/appointment_settings) با مجوز نمایش داده میشوند", () => {
|
||||
setSecretary({
|
||||
staff: { view: true },
|
||||
discounts: { view: true },
|
||||
sms: { view: true },
|
||||
appointment_settings: { view: true },
|
||||
});
|
||||
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
|
||||
expect(screen.getByText("پرسنل").closest("a")).toHaveAttribute("href", "/admin/staff");
|
||||
expect(screen.getByText("تخفیفها").closest("a")).toHaveAttribute("href", "/admin/discounts");
|
||||
expect(screen.getByText("پیامکها").closest("a")).toHaveAttribute("href", "/admin/sms-wallet");
|
||||
// scope=clinic → مسیر تنظیمات کلینیک
|
||||
expect(screen.getByText("تنظیمات نوبتدهی").closest("a")).toHaveAttribute(
|
||||
"href",
|
||||
"/admin/settings/appointment-settings",
|
||||
);
|
||||
});
|
||||
|
||||
it("مدیریت پزشکان کلینیک در scope=doctor حتی با مجوز دیده نمیشود", () => {
|
||||
useAuthStore.setState({
|
||||
primaryRole: "secretary",
|
||||
dbUuid: "d1",
|
||||
userName: "منشی",
|
||||
availableContexts: [],
|
||||
context: { scope: "doctor", permissions: { resources: { clinic_doctors: { view: true } } } },
|
||||
} as any);
|
||||
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
|
||||
expect(screen.queryByText("پزشکان کلینیک")).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
it("مدیریت پزشکان کلینیک در scope=clinic با مجوز دیده میشود", () => {
|
||||
setSecretary({ clinic_doctors: { view: true } });
|
||||
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
|
||||
expect(screen.getByText("پزشکان کلینیک").closest("a")).toHaveAttribute(
|
||||
"href",
|
||||
"/admin/settings/clinic-doctors",
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -18,6 +18,7 @@ import {
|
||||
KeyIcon,
|
||||
LockClosedIcon,
|
||||
PlusIcon,
|
||||
ReceiptPercentIcon,
|
||||
ShieldCheckIcon,
|
||||
StarIcon,
|
||||
TagIcon,
|
||||
@@ -422,6 +423,46 @@ function buildSections(
|
||||
label: "تگها",
|
||||
});
|
||||
}
|
||||
if (can("staff", "view")) {
|
||||
items.push({
|
||||
to: "/admin/staff",
|
||||
icon: UsersIcon,
|
||||
label: "پرسنل",
|
||||
});
|
||||
}
|
||||
if (can("discounts", "view")) {
|
||||
items.push({
|
||||
to: "/admin/discounts",
|
||||
icon: ReceiptPercentIcon,
|
||||
label: "تخفیفها",
|
||||
});
|
||||
}
|
||||
if (can("sms", "view")) {
|
||||
items.push({
|
||||
to: "/admin/sms-wallet",
|
||||
icon: DevicePhoneMobileIcon,
|
||||
label: "پیامکها",
|
||||
});
|
||||
}
|
||||
if (can("appointment_settings", "view")) {
|
||||
items.push({
|
||||
// مسیر بسته به محیط فعال: کلینیک vs مطب شخصی.
|
||||
to:
|
||||
scope === "clinic"
|
||||
? "/admin/settings/appointment-settings"
|
||||
: "/admin/appointment-settings",
|
||||
icon: Cog6ToothIcon,
|
||||
label: "تنظیمات نوبتدهی",
|
||||
});
|
||||
}
|
||||
// مدیریت پزشکان کلینیک فقط در محیطِ کلینیک معنا دارد.
|
||||
if (scope === "clinic" && can("clinic_doctors", "view")) {
|
||||
items.push({
|
||||
to: "/admin/settings/clinic-doctors",
|
||||
icon: HeartIcon,
|
||||
label: "پزشکان کلینیک",
|
||||
});
|
||||
}
|
||||
|
||||
return [
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user