feat(auth): enable event-scoped admin access and backfill staff assignments
This commit is contained in:
@@ -0,0 +1,44 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
DB::transaction(function (): void {
|
||||
DB::table('tenants')
|
||||
->join('events', 'events.id', '=', 'tenants.active_event_id')
|
||||
->whereColumn('events.tenant_code', 'tenants.codigo')
|
||||
->select('tenants.codigo', 'tenants.active_event_id')
|
||||
->get()
|
||||
->each(function (object $tenant): void {
|
||||
DB::table('users')
|
||||
->whereIn('rol_codigo', ['adminapp', 'scanner'])
|
||||
->where('tenant_codigo', $tenant->codigo)
|
||||
->where('admin_scope', 'tenant')
|
||||
->whereNull('event_id')
|
||||
->whereNull('deleted_at')
|
||||
->update([
|
||||
'admin_scope' => 'event',
|
||||
'event_id' => $tenant->active_event_id,
|
||||
'updated_at' => now(),
|
||||
]);
|
||||
});
|
||||
|
||||
// Missing or mismatched active events must not leave legacy staff with tenant-wide access.
|
||||
DB::table('users')
|
||||
->whereIn('rol_codigo', ['adminapp', 'scanner'])
|
||||
->where('admin_scope', 'tenant')
|
||||
->whereNull('event_id')
|
||||
->whereNull('deleted_at')
|
||||
->update(['admin_scope' => 'event', 'updated_at' => now()]);
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
// Do not broaden permissions or overwrite subsequent assignments on rollback.
|
||||
}
|
||||
};
|
||||
Reference in New Issue
Block a user