This commit is contained in:
2026-09-01 13:43:05 +05:30
parent ab74e70ba5
commit 6b27448ff9

View File

@@ -651,7 +651,24 @@ func (r *tenantRepository) CreateTenantUser(data models.Tenants) (bool, error) {
user.Deviceid = data.Deviceid
user.Tenantid = data.Tenantid
user.Locationid = data.Tenantlocations.Locationid
user.Roleid = 1
// A merchant's own administrator is an ADMIN (3), not a Super admin (1).
//
// This wrote 1, and `app_roles` calls 1 "Super admin" — so every shop on the
// platform was provisioned with an account that reads as a platform
// operator on its own Users & access screen. It never had platform access:
// that is `app_users.issuperadmin`, a separate column the console checks
// first, and no store account has it set. But a label saying "Super admin"
// on a merchant's staff list is a thing somebody will eventually act on.
//
// 3 also matches the old console's ladder, which this one is meant to
// follow: Super Admin = platform, Admin = the merchant group, Manager (4) =
// a single store. `rmartuser` and `Kmartuser` — the store users there — are
// both roleid 4.
//
// Existing tenants keep roleid 1 and keep working: `resolveRole` still
// treats 1 and 3 alike, deliberately, because changing that would lock out
// every merchant provisioned before today.
user.Roleid = 3
// The onboarding form never sends a tenant configid, so copier.Copy left
// this at zero — AppLogin's GetUserByAuthname always queries configid=1
// for the web login, so a zero here makes the account permanently