The consumer app resolves a storefront by scanning a QR that encodes
{tenantid, locationid}. Store Onboarding was creating the location but never
surfacing its QR, so operators had to hunt for it later in the store detail
view. Now that the backend returns the created location's locationid in the
onboarding response, render the existing StoreQRView component directly in
the "Store Branch Active!" success panel (both onboarding UI variants) so the
printable QR is available the moment the branch is created.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
UsersPanel.tsx was sending configid: 15 (Staff) / 6 (Rider) when creating
users, copied from an unrelated Hasura "role config" convention. Every
login call (auth.ts) queries app_users with configid: 1, so any account
created with 15/6 could never be found on login and was stuck before it
even reached the password-setup step. Both create paths and the
CreateUserInput default now consistently use configid: 1.
Also fixes getRiderLogs() calling riders/getriderlogs, which 404s since
the backend only registers this route under /partners.
Accounts created by tenant/store onboarding (createtenantuser,
createtenantlocation) have no password set. Previously the login form
treated the backend's "please setup a password" response as a
successful login instead of prompting for one. Now auth.ts recognizes
it (PasswordSetupRequiredError) and LoginView routes to a create-
password step, then signs in immediately with the new password.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
super_admin is now a real LoginRole, derived from the server's
issuperadmin flag (not a client-guessable roleid) — routes exclusively
to a new minimal SuperAdminPage, never the merchant console.
That page reuses the existing tenant/store/rider onboarding wizard
(AdminConsole) rather than duplicating it — its Tenant tab was already
calling the right composite endpoint but had nowhere to send location
data, and was never actually reachable from anywhere in the app. Now
it collects a primary outlet name + business category and sends a
nested tenantlocations object, so one submit provisions tenant +
active location + admin user instead of leaving the tenant
locationless. createTenantUser also moves off the mob API base onto
the web one, matching where this is actually called from.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>