Skip to content

separate staff accounts from customer identities (backend user model) #101

Description

@jaspermayone

Why

Weave currently models staff as role flags on the customer User. At Hack Club scale the backoffice identity should be decoupled from the public identity: service accounts with no public profile, staff whose customer account is independent of their admin access, and clean deprovisioning (kill the staff account, the person's normal account survives — deletion pipeline #94 also refuses to erase admin accounts cleanly when the two are entangled).

What

Adopt the hackclub/auth Backend::User pattern:

  • Distinct model/table, belongs_to :user, optional: true (linked or orphaned/service accounts).
  • Capabilities as boolean columns exposed as predicates (super_admin?, can_break_glass?, can_process_deletions?, program_manager?, …) + active? — matching Pundit policies (adopt pundit with fail-closed policies #88) and view capability wrappers.
  • Admin base controller resolves current_admin = current_user&.backend_user, rejects inactive; namespace-wide 2FA gate (Admin accounts / anyone with more than user access MUST require 2fa #81) sits here.
  • Migrate the existing role enum (admin/superadmin/owner) into backend_users; the customer role column eventually reduces to plain user.
  • Keep the orthogonal profile flags (is_board, is_staff, is_contractor) on User — they describe the person, not admin capability.

Reference

Notes

Sequence AFTER Pundit (#88): policies keep a single user type per context, avoiding their hackclub/auth#191 mess. Impersonation and audit whodunnit must record the backend user.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestmigrationIncludes database migrations

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions