feat: add account roles audit and task authorization

This commit is contained in:
inman committed 2026-09-01 19:14:06 +08:00
1 parent 337aaf7c88
commit 191c1a1aad
15 files changed
+4961 -457

No files matched your search

@@ -0,0 +1,24 @@
-- Add the fixed-scope team-lead role and read-only operations-dashboard indexes.
-- This remains a single-organization deployment; no tenant selector is added.
ALTER TABLE users
DROP CONSTRAINT IF EXISTS users_role_check;
ALTER TABLE users
ADD CONSTRAINT users_role_check CHECK (role IN ('admin', 'team_lead', 'user'));
CREATE INDEX IF NOT EXISTS tasks_operations_dashboard_created_idx
ON tasks (organization_id, created_at DESC, id DESC)
WHERE source = 'manual';
CREATE INDEX IF NOT EXISTS tasks_operations_dashboard_actor_idx
ON tasks (organization_id, created_by, created_at DESC, id DESC)
WHERE source = 'manual';
CREATE INDEX IF NOT EXISTS tasks_operations_dashboard_status_idx
ON tasks (organization_id, status, created_at DESC, id DESC)
WHERE source = 'manual';
CREATE INDEX IF NOT EXISTS tasks_operations_dashboard_business_idx
ON tasks (organization_id, business_route_id, created_at DESC, id DESC)
WHERE source = 'manual';