feat: refactor super admin to use is_super_admin flag and enhance site deletion logic
- Changed super admin detection from role-based to `is_super_admin` flag in AdminUser model
- Added `requireDefaultAdminSiteId()` method to throw validation error when no integration site exists
- Enhanced site deletion to migrate platform role bindings to fallback site and auto-delete site-specific admin accounts
- Made agent line code optional with auto-generation fallback using `{site_code}-agent-{counter}` format
This commit is contained in:
@@ -38,6 +38,7 @@ final class AdminAuthProfile
|
||||
* can_create_child_agent: bool,
|
||||
* can_create_player: bool
|
||||
* },
|
||||
* site: ?array{id: int, code: string, name: string},
|
||||
* is_super_admin: bool,
|
||||
* operational_permissions: list<string>,
|
||||
* delegation_ceiling: list<string>,
|
||||
@@ -58,6 +59,7 @@ final class AdminAuthProfile
|
||||
'permissions' => $permissionSlugs,
|
||||
'navigation' => AdminAuthorizationRegistry::visibleNavigationItems($permissionSlugs, $fresh),
|
||||
'agent' => $agent,
|
||||
'site' => self::siteContext($fresh),
|
||||
'is_super_admin' => $fresh->isSuperAdmin(),
|
||||
'operational_permissions' => $permissionSlugs,
|
||||
'delegation_ceiling' => AgentDelegationAuthorization::delegationLegacySlugsForAdminUser($fresh),
|
||||
@@ -71,19 +73,32 @@ final class AdminAuthProfile
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{
|
||||
* id: int,
|
||||
* admin_site_id: int,
|
||||
* admin_site_name: string,
|
||||
* site_code: string,
|
||||
* path: string,
|
||||
* code: string,
|
||||
* name: string,
|
||||
* depth: int,
|
||||
* can_create_child_agent: bool,
|
||||
* can_create_player: bool
|
||||
* }|null
|
||||
* @return array{id: int, code: string, name: string}|null
|
||||
*/
|
||||
private static function siteContext(AdminUser $admin): ?array
|
||||
{
|
||||
if ($admin->isSuperAdmin() || $admin->primaryAgentNode() !== null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
if (! SitePlatformRole::userHasSiteAdminRole($admin)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$sites = AdminUserSiteBindingPresenter::accessibleSitesFor($admin);
|
||||
if ($sites === []) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$site = $sites[0];
|
||||
|
||||
return [
|
||||
'id' => (int) $site['id'],
|
||||
'code' => (string) $site['code'],
|
||||
'name' => (string) $site['name'],
|
||||
];
|
||||
}
|
||||
|
||||
private static function agentContext(AdminUser $admin): ?array
|
||||
{
|
||||
if ($admin->isSuperAdmin()) {
|
||||
|
||||
Reference in New Issue
Block a user