The platform admin's last shell-only jobs are endpoints

Suspend or reinstate a company (PATCH /api/admin/clients/{id}), reset
its owner's password (shown once), and delete it - and an owner can
remove a shop opened by mistake (DELETE /api/sites/{site}, empty only).

Suspension ends every session the company holds in the same
transaction: login and ingest already refused an inactive client, but a
live access token would have kept reading for up to twelve hours, so
'suspend' would have meant 'suspend some time tomorrow'. Deletion is
deliberately two steps - the company must already be suspended and the
request repeats the slug - because the data under it is biometric.
Face images go first (a storage failure aborts with nothing touched),
then the broker logins, then the rows by cascade.

Exercised against the local Postgres and broker: create, open a shop,
remove it (two plugin commands), refuse delete while active, suspend
(owner's token 401 immediately), reset, delete, zero rows left.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
This commit is contained in:
2026-09-19 12:36:21 +05:30
parent c93fbff31f
commit 8786a5b0b4
8 changed files with 686 additions and 9 deletions

View File

@@ -502,6 +502,75 @@ func (f *fakeStore) ReleaseStaleChecks(_ context.Context, _ time.Duration) error
return nil
}
func (f *fakeStore) SetClientActive(_ context.Context, clientID string, active bool) (ClientRow, int, error) {
f.mu.Lock()
defer f.mu.Unlock()
for i := range f.clients {
if f.clients[i].ID != clientID {
continue
}
f.clients[i].Active = active
revoked := 0
if !active {
for _, sess := range f.sessions {
if sess.p.ClientID == clientID && !sess.revoked {
sess.revoked = true
revoked++
}
}
}
return f.clients[i], revoked, nil
}
return ClientRow{}, 0, pgx.ErrNoRows
}
func (f *fakeStore) ClientOwners(_ context.Context, clientID string) ([]TeamMember, error) {
f.mu.Lock()
defer f.mu.Unlock()
var out []TeamMember
for _, u := range f.users {
if u.ClientID == clientID && u.Role == "owner" && u.Active {
out = append(out, TeamMember{ID: u.ID, Email: u.Email, FullName: u.FullName, Role: u.Role, Active: u.Active})
}
}
return out, nil
}
func (f *fakeStore) ClientImageKeys(_ context.Context, _ string) ([]string, error) { return nil, nil }
func (f *fakeStore) DeleteClient(_ context.Context, clientID string) (ClientRow, []string, error) {
f.mu.Lock()
defer f.mu.Unlock()
for i, c := range f.clients {
if c.ID != clientID {
continue
}
if c.Active {
return c, nil, errors.New("client is active")
}
f.clients = append(f.clients[:i], f.clients[i+1:]...)
return c, []string{c.Slug + ".shop1"}, nil
}
return ClientRow{}, nil, pgx.ErrNoRows
}
func (f *fakeStore) DeleteEmptySite(_ context.Context, _ string, siteID string) (string, error) {
f.mu.Lock()
defer f.mu.Unlock()
for _, c := range f.cameras {
if c.SiteID == siteID {
return "", ErrSiteInUse
}
}
for i, s := range f.sites {
if s.SiteID == siteID {
f.sites = append(f.sites[:i], f.sites[i+1:]...)
return "acme." + s.Slug, nil
}
}
return "", pgx.ErrNoRows
}
func (f *fakeStore) ListClients(_ context.Context) ([]ClientRow, error) {
f.mu.Lock()
defer f.mu.Unlock()