Add ClubRole (ADMIN / MEMBER / EDITOR, one per member per club) and complete club/services/access.py — the single module all authorisation routes through: - teams_managed_by / can_edit_event -> authority: a *management* StaffAssignment in the *current season*; ADMIN overrides club-wide. A StaffAssignment is per-season, so a former coach's authority expires with it. - teams_staffed_by -> visibility: *any* staff position, so support staff (physio, kit manager) can see the roster they work with without gaining authority. - members_visible_to -> ADMIN sees everyone linked to the club; otherwise self + children (family graph) + the current-season players and staff of the teams they're staffed on. - can_edit_event -> ADMIN/EDITOR, the event's owner, or a manager of one of its teams for that event's season. - can_manage_shop -> ADMIN. Fix roles_in_club, which called .unique() — not a QuerySet method, so it would have raised AttributeError on first use. Keep ClubRole in sync with membership status: an active ClubMembership grants the MEMBER role and losing it withdraws that role — but an elevated role (ADMIN/EDITOR) is never downgraded or removed, so a lapsed membership or a season rollover can never lock an admin out. Validate ClubMembership.season against the membership's club. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
40 lines
1.4 KiB
Python
40 lines
1.4 KiB
Python
"""Keep ClubRole in sync with membership status.
|
|
|
|
An **active** ClubMembership grants the member a ``MEMBER`` ClubRole; when no
|
|
active membership remains in that club (status changed away from active, or the
|
|
membership was deleted), the ``MEMBER`` role is withdrawn.
|
|
|
|
A member holds at most one ClubRole per club (``unique_member_per_club``), so an
|
|
elevated role (ADMIN / EDITOR) is never downgraded or removed by this sync — it
|
|
simply takes precedence.
|
|
"""
|
|
|
|
from django.db.models.signals import post_delete, post_save
|
|
from django.dispatch import receiver
|
|
|
|
from .models import ClubMembership, ClubRole
|
|
|
|
|
|
@receiver(post_save, sender=ClubMembership)
|
|
@receiver(post_delete, sender=ClubMembership)
|
|
def sync_member_role(sender, instance, **kwargs):
|
|
has_active = ClubMembership.objects.filter(
|
|
club_id=instance.club_id,
|
|
member_id=instance.member_id,
|
|
status=ClubMembership.StatusChoices.ACTIVE,
|
|
).exists()
|
|
|
|
if has_active:
|
|
# get_or_create keeps an existing ADMIN/EDITOR role untouched.
|
|
ClubRole.objects.get_or_create(
|
|
club_id=instance.club_id,
|
|
member_id=instance.member_id,
|
|
defaults={"role": ClubRole.Roles.MEMBER},
|
|
)
|
|
else:
|
|
ClubRole.objects.filter(
|
|
club_id=instance.club_id,
|
|
member_id=instance.member_id,
|
|
role=ClubRole.Roles.MEMBER,
|
|
).delete()
|