You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Weave currently models staff as role flags on the customer User. At Hack Club scale the backoffice identity should be decoupled from the public identity: service accounts with no public profile, staff whose customer account is independent of their admin access, and clean deprovisioning (kill the staff account, the person's normal account survives — deletion pipeline #94 also refuses to erase admin accounts cleanly when the two are entangled).
What
Adopt the hackclub/auth Backend::User pattern:
Distinct model/table, belongs_to :user, optional: true (linked or orphaned/service accounts).
Capabilities as boolean columns exposed as predicates (super_admin?, can_break_glass?, can_process_deletions?, program_manager?, …) + active? — matching Pundit policies (adopt pundit with fail-closed policies #88) and view capability wrappers.
Sequence AFTER Pundit (#88): policies keep a single user type per context, avoiding their hackclub/auth#191 mess. Impersonation and audit whodunnit must record the backend user.
Why
Weave currently models staff as role flags on the customer
User. At Hack Club scale the backoffice identity should be decoupled from the public identity: service accounts with no public profile, staff whose customer account is independent of their admin access, and clean deprovisioning (kill the staff account, the person's normal account survives — deletion pipeline #94 also refuses to erase admin accounts cleanly when the two are entangled).What
Adopt the hackclub/auth
Backend::Userpattern:belongs_to :user, optional: true(linked or orphaned/service accounts).super_admin?,can_break_glass?,can_process_deletions?,program_manager?, …) +active?— matching Pundit policies (adopt pundit with fail-closed policies #88) and view capability wrappers.current_admin = current_user&.backend_user, rejects inactive; namespace-wide 2FA gate (Admin accounts / anyone with more than user access MUST require 2fa #81) sits here.admin/superadmin/owner) into backend_users; the customerrolecolumn eventually reduces to plainuser.is_board,is_staff,is_contractor) on User — they describe the person, not admin capability.Reference
Notes
Sequence AFTER Pundit (#88): policies keep a single user type per context, avoiding their hackclub/auth#191 mess. Impersonation and audit whodunnit must record the backend user.