role id
This commit is contained in:
@@ -651,7 +651,24 @@ func (r *tenantRepository) CreateTenantUser(data models.Tenants) (bool, error) {
|
||||
user.Deviceid = data.Deviceid
|
||||
user.Tenantid = data.Tenantid
|
||||
user.Locationid = data.Tenantlocations.Locationid
|
||||
user.Roleid = 1
|
||||
// A merchant's own administrator is an ADMIN (3), not a Super admin (1).
|
||||
//
|
||||
// This wrote 1, and `app_roles` calls 1 "Super admin" — so every shop on the
|
||||
// platform was provisioned with an account that reads as a platform
|
||||
// operator on its own Users & access screen. It never had platform access:
|
||||
// that is `app_users.issuperadmin`, a separate column the console checks
|
||||
// first, and no store account has it set. But a label saying "Super admin"
|
||||
// on a merchant's staff list is a thing somebody will eventually act on.
|
||||
//
|
||||
// 3 also matches the old console's ladder, which this one is meant to
|
||||
// follow: Super Admin = platform, Admin = the merchant group, Manager (4) =
|
||||
// a single store. `rmartuser` and `Kmartuser` — the store users there — are
|
||||
// both roleid 4.
|
||||
//
|
||||
// Existing tenants keep roleid 1 and keep working: `resolveRole` still
|
||||
// treats 1 and 3 alike, deliberately, because changing that would lock out
|
||||
// every merchant provisioned before today.
|
||||
user.Roleid = 3
|
||||
// The onboarding form never sends a tenant configid, so copier.Copy left
|
||||
// this at zero — AppLogin's GetUserByAuthname always queries configid=1
|
||||
// for the web login, so a zero here makes the account permanently
|
||||
|
||||
Reference in New Issue
Block a user