a1a816b4a5
* Implement company and account deletion features - Add event types for company and account deletion to CoreEvent. - Enhance Supabase middleware to handle company context resolution and cookie management for archived companies. - Create API routes for deleting accounts and companies, including necessary validations and event emissions. - Implement tests for account and company deletion endpoints to ensure proper functionality and error handling. - Add retention notice component to inform users about bookkeeping data retention during destructive actions. - Create database migrations to support soft deletion of companies and anonymization of user accounts, ensuring compliance with retention laws. * feat: enhance account deletion process and update user notifications * Add service client for onboarding completion check and update escape hatch visibility * Enhance invite flow and email handling for company members * Refactor company context and RLS policies for active company isolation - Update `switchCompany` to remove unnecessary revalidation as client handles navigation. - Revise `getActiveCompanyId` to prioritize `user_preferences` and validate against non-archived memberships. - Modify `setActiveCompany` to ensure `user_preferences` is the authoritative source while maintaining cookie compatibility. - Enhance middleware to resolve active company using `user_preferences` and fallback to first non-archived membership. - Introduce new API route `/api/company/current` to fetch the active company ID for cross-tab synchronization. - Implement `CompanyTabSync` component for real-time active company enforcement across tabs. - Create migration for RLS policies to enforce single-active-company isolation using `current_active_company_id()`. * feat: implement viewer role enforcement for write permissions - Added `useCanWrite` hook to determine if the current user has write permissions based on their role in the active company. - Updated various components (JournalEntryForm, CustomerForm, DeadlineForm, etc.) to disable write actions and show a lock icon with a tooltip for users without write permissions. - Introduced `requireWritePermission` function to enforce write permissions at the API level, returning a 403 response for viewers. - Created tests to verify the behavior of the viewer role and write permissions. - Added database migration to enforce read-only access for viewers at the database level.
24 lines
933 B
TypeScript
24 lines
933 B
TypeScript
'use client'
|
|
|
|
import { useCompany } from '@/contexts/CompanyContext'
|
|
|
|
/**
|
|
* Returns whether the current user can perform write actions in the
|
|
* active company. Viewers (role === 'viewer') get `canWrite = false`;
|
|
* owner / admin / member all get `canWrite = true`. Users with no active
|
|
* company (null role) also get `canWrite = false`.
|
|
*
|
|
* Used by every write-action button (create / edit / delete / send /
|
|
* approve / etc.) across the dashboard to render the button in a
|
|
* disabled state with a lock icon and tooltip.
|
|
*
|
|
* This is the UI layer of the viewer role enforcement. The API layer
|
|
* (`requireWritePermission()`) and RLS layer (`current_user_can_write()`)
|
|
* remain the security-critical backstops — this hook only controls what
|
|
* the user sees and can click.
|
|
*/
|
|
export function useCanWrite(): { canWrite: boolean } {
|
|
const { role } = useCompany()
|
|
return { canWrite: role !== null && role !== 'viewer' }
|
|
}
|