feat(secretary): grant staff/discounts/sms/appointment_settings/clinic_doctors (phase B)

Extends the secretary permission system to five previously owner-only modules,
so a clinic/doctor can delegate each page to a secretary. All were unreachable
by secretaries before (role-based tenant resolution returned "unknown" → 403).

New permission resources (default-deny, three-place add: entity default,
SecretaryPermissions type, both MySecretariesPage + admin SecretariesPage):
staff, discounts, sms, appointment_settings (view/update only), clinic_doctors
(clinic-only — hidden from independent doctors via `clinicOnly` section filter).

Backend enforcement (SecretaryAccessChecker, three new reusable helpers):
- resolveOwnerEntity(): owner pair from active context — used by StaffController,
  DiscountController, SmsWalletController (now secretary-aware resolveEntity).
- canForDoctor(): per-doctor-scoped check (assigned doctor + toggle) — wired into
  AppointmentSettingsController::denyDoctorAccess.
- canForClinic(): clinic-scoped check — wired into ClinicController::detachDoctor,
  ClinicDoctorPermissionController (view/update), ClinicInvitationController
  (create/view/update/delete). clinic_doctors is clinic-context only.
Guards run ahead of any subscription gate; non-secretary roles pass unchanged.

Frontend:
- RoleRoute: staff, discounts, sms-wallet, appointment-settings (doctor+clinic
  variants), settings/clinic-doctors routes accept secretary + permission gate.
- Sidebar (secretary branch): five new items gated by can(); appointment_settings
  route follows active scope; clinic_doctors only in clinic scope.

Tests: SecretaryResourceEnforcementTest — denied-by-default + allowed-when-granted
for all five (18 total). Sidebar.test — B-resource gating + clinic_doctors scope
rule. docs/api/secretary.md resource list, enforcement map, JSON example updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
hamed
2026-07-23 17:29:51 +03:30
co-authored by Claude Opus 4.8
parent b9189700b3
commit e8bf2ce9b1
17 changed files with 486 additions and 22 deletions
@@ -116,4 +116,43 @@ describe("Sidebar — گِیت منوی منشی بر اساس مجوز", () =>
"/admin/tags-settings",
);
});
it("منابع فاز B (staff/discounts/sms/appointment_settings) با مجوز نمایش داده می‌شوند", () => {
setSecretary({
staff: { view: true },
discounts: { view: true },
sms: { view: true },
appointment_settings: { view: true },
});
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
expect(screen.getByText("پرسنل").closest("a")).toHaveAttribute("href", "/admin/staff");
expect(screen.getByText("تخفیف‌ها").closest("a")).toHaveAttribute("href", "/admin/discounts");
expect(screen.getByText("پیامک‌ها").closest("a")).toHaveAttribute("href", "/admin/sms-wallet");
// scope=clinic → مسیر تنظیمات کلینیک
expect(screen.getByText("تنظیمات نوبت‌دهی").closest("a")).toHaveAttribute(
"href",
"/admin/settings/appointment-settings",
);
});
it("مدیریت پزشکان کلینیک در scope=doctor حتی با مجوز دیده نمی‌شود", () => {
useAuthStore.setState({
primaryRole: "secretary",
dbUuid: "d1",
userName: "منشی",
availableContexts: [],
context: { scope: "doctor", permissions: { resources: { clinic_doctors: { view: true } } } },
} as any);
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
expect(screen.queryByText("پزشکان کلینیک")).not.toBeInTheDocument();
});
it("مدیریت پزشکان کلینیک در scope=clinic با مجوز دیده می‌شود", () => {
setSecretary({ clinic_doctors: { view: true } });
renderWithProviders(<Sidebar />, { route: "/admin/dashboard" });
expect(screen.getByText("پزشکان کلینیک").closest("a")).toHaveAttribute(
"href",
"/admin/settings/clinic-doctors",
);
});
});
@@ -18,6 +18,7 @@ import {
KeyIcon,
LockClosedIcon,
PlusIcon,
ReceiptPercentIcon,
ShieldCheckIcon,
StarIcon,
TagIcon,
@@ -422,6 +423,46 @@ function buildSections(
label: "تگ‌ها",
});
}
if (can("staff", "view")) {
items.push({
to: "/admin/staff",
icon: UsersIcon,
label: "پرسنل",
});
}
if (can("discounts", "view")) {
items.push({
to: "/admin/discounts",
icon: ReceiptPercentIcon,
label: "تخفیف‌ها",
});
}
if (can("sms", "view")) {
items.push({
to: "/admin/sms-wallet",
icon: DevicePhoneMobileIcon,
label: "پیامک‌ها",
});
}
if (can("appointment_settings", "view")) {
items.push({
// مسیر بسته به محیط فعال: کلینیک vs مطب شخصی.
to:
scope === "clinic"
? "/admin/settings/appointment-settings"
: "/admin/appointment-settings",
icon: Cog6ToothIcon,
label: "تنظیمات نوبت‌دهی",
});
}
// مدیریت پزشکان کلینیک فقط در محیطِ کلینیک معنا دارد.
if (scope === "clinic" && can("clinic_doctors", "view")) {
items.push({
to: "/admin/settings/clinic-doctors",
icon: HeartIcon,
label: "پزشکان کلینیک",
});
}
return [
{