diff --git a/repositories/tenantRepository.go b/repositories/tenantRepository.go index c7bc24c..eb91688 100644 --- a/repositories/tenantRepository.go +++ b/repositories/tenantRepository.go @@ -651,7 +651,24 @@ func (r *tenantRepository) CreateTenantUser(data models.Tenants) (bool, error) { user.Deviceid = data.Deviceid user.Tenantid = data.Tenantid user.Locationid = data.Tenantlocations.Locationid - user.Roleid = 1 + // A merchant's own administrator is an ADMIN (3), not a Super admin (1). + // + // This wrote 1, and `app_roles` calls 1 "Super admin" — so every shop on the + // platform was provisioned with an account that reads as a platform + // operator on its own Users & access screen. It never had platform access: + // that is `app_users.issuperadmin`, a separate column the console checks + // first, and no store account has it set. But a label saying "Super admin" + // on a merchant's staff list is a thing somebody will eventually act on. + // + // 3 also matches the old console's ladder, which this one is meant to + // follow: Super Admin = platform, Admin = the merchant group, Manager (4) = + // a single store. `rmartuser` and `Kmartuser` — the store users there — are + // both roleid 4. + // + // Existing tenants keep roleid 1 and keep working: `resolveRole` still + // treats 1 and 3 alike, deliberately, because changing that would lock out + // every merchant provisioned before today. + user.Roleid = 3 // The onboarding form never sends a tenant configid, so copier.Copy left // this at zero — AppLogin's GetUserByAuthname always queries configid=1 // for the web login, so a zero here makes the account permanently