Files
RosterChief/club/signals.py
Bernard Siebens 819700ad0c feat(club): ClubRole, RBAC access service and role sync
Add ClubRole (ADMIN / MEMBER / EDITOR, one per member per club) and complete
club/services/access.py — the single module all authorisation routes through:

- teams_managed_by / can_edit_event  -> authority: a *management* StaffAssignment
  in the *current season*; ADMIN overrides club-wide. A StaffAssignment is
  per-season, so a former coach's authority expires with it.
- teams_staffed_by -> visibility: *any* staff position, so support staff (physio,
  kit manager) can see the roster they work with without gaining authority.
- members_visible_to -> ADMIN sees everyone linked to the club; otherwise self +
  children (family graph) + the current-season players and staff of the teams
  they're staffed on.
- can_edit_event -> ADMIN/EDITOR, the event's owner, or a manager of one of its
  teams for that event's season.
- can_manage_shop -> ADMIN.

Fix roles_in_club, which called .unique() — not a QuerySet method, so it would
have raised AttributeError on first use.

Keep ClubRole in sync with membership status: an active ClubMembership grants
the MEMBER role and losing it withdraws that role — but an elevated role
(ADMIN/EDITOR) is never downgraded or removed, so a lapsed membership or a
season rollover can never lock an admin out.

Validate ClubMembership.season against the membership's club.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 14:43:15 +02:00

40 lines
1.4 KiB
Python

"""Keep ClubRole in sync with membership status.
An **active** ClubMembership grants the member a ``MEMBER`` ClubRole; when no
active membership remains in that club (status changed away from active, or the
membership was deleted), the ``MEMBER`` role is withdrawn.
A member holds at most one ClubRole per club (``unique_member_per_club``), so an
elevated role (ADMIN / EDITOR) is never downgraded or removed by this sync — it
simply takes precedence.
"""
from django.db.models.signals import post_delete, post_save
from django.dispatch import receiver
from .models import ClubMembership, ClubRole
@receiver(post_save, sender=ClubMembership)
@receiver(post_delete, sender=ClubMembership)
def sync_member_role(sender, instance, **kwargs):
has_active = ClubMembership.objects.filter(
club_id=instance.club_id,
member_id=instance.member_id,
status=ClubMembership.StatusChoices.ACTIVE,
).exists()
if has_active:
# get_or_create keeps an existing ADMIN/EDITOR role untouched.
ClubRole.objects.get_or_create(
club_id=instance.club_id,
member_id=instance.member_id,
defaults={"role": ClubRole.Roles.MEMBER},
)
else:
ClubRole.objects.filter(
club_id=instance.club_id,
member_id=instance.member_id,
role=ClubRole.Roles.MEMBER,
).delete()