feat(club): ClubRole, RBAC access service and role sync
Add ClubRole (ADMIN / MEMBER / EDITOR, one per member per club) and complete club/services/access.py — the single module all authorisation routes through: - teams_managed_by / can_edit_event -> authority: a *management* StaffAssignment in the *current season*; ADMIN overrides club-wide. A StaffAssignment is per-season, so a former coach's authority expires with it. - teams_staffed_by -> visibility: *any* staff position, so support staff (physio, kit manager) can see the roster they work with without gaining authority. - members_visible_to -> ADMIN sees everyone linked to the club; otherwise self + children (family graph) + the current-season players and staff of the teams they're staffed on. - can_edit_event -> ADMIN/EDITOR, the event's owner, or a manager of one of its teams for that event's season. - can_manage_shop -> ADMIN. Fix roles_in_club, which called .unique() — not a QuerySet method, so it would have raised AttributeError on first use. Keep ClubRole in sync with membership status: an active ClubMembership grants the MEMBER role and losing it withdraws that role — but an elevated role (ADMIN/EDITOR) is never downgraded or removed, so a lapsed membership or a season rollover can never lock an admin out. Validate ClubMembership.season against the membership's club. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
39
club/signals.py
Normal file
39
club/signals.py
Normal file
@@ -0,0 +1,39 @@
|
||||
"""Keep ClubRole in sync with membership status.
|
||||
|
||||
An **active** ClubMembership grants the member a ``MEMBER`` ClubRole; when no
|
||||
active membership remains in that club (status changed away from active, or the
|
||||
membership was deleted), the ``MEMBER`` role is withdrawn.
|
||||
|
||||
A member holds at most one ClubRole per club (``unique_member_per_club``), so an
|
||||
elevated role (ADMIN / EDITOR) is never downgraded or removed by this sync — it
|
||||
simply takes precedence.
|
||||
"""
|
||||
|
||||
from django.db.models.signals import post_delete, post_save
|
||||
from django.dispatch import receiver
|
||||
|
||||
from .models import ClubMembership, ClubRole
|
||||
|
||||
|
||||
@receiver(post_save, sender=ClubMembership)
|
||||
@receiver(post_delete, sender=ClubMembership)
|
||||
def sync_member_role(sender, instance, **kwargs):
|
||||
has_active = ClubMembership.objects.filter(
|
||||
club_id=instance.club_id,
|
||||
member_id=instance.member_id,
|
||||
status=ClubMembership.StatusChoices.ACTIVE,
|
||||
).exists()
|
||||
|
||||
if has_active:
|
||||
# get_or_create keeps an existing ADMIN/EDITOR role untouched.
|
||||
ClubRole.objects.get_or_create(
|
||||
club_id=instance.club_id,
|
||||
member_id=instance.member_id,
|
||||
defaults={"role": ClubRole.Roles.MEMBER},
|
||||
)
|
||||
else:
|
||||
ClubRole.objects.filter(
|
||||
club_id=instance.club_id,
|
||||
member_id=instance.member_id,
|
||||
role=ClubRole.Roles.MEMBER,
|
||||
).delete()
|
||||
Reference in New Issue
Block a user