@@ -28,46 +28,79 @@ type RolePermissions = {
2828
2929type PermissionKey = keyof RolePermissions ;
3030
31- // Map specific settings routes to their respective permission keys.
31+ // Admin-only cards that require role_id = 1
32+ const ADMIN_ONLY_PATHS = [
33+ "/home/settings/news-banners" ,
34+ "/home/settings/services" ,
35+ ] ;
36+
37+ // Map specific settings routes to their respective permission keys
3238const settingsPermissionMap : Record < string , PermissionKey > = {
3339 "/home/settings/profile" : "resume" ,
3440 "/home/settings/permissions" : "permissions" ,
3541 "/home/settings/roles" : "roles" ,
36- "/home/settings/news-banners" : "settings" , // Admin-only feature
3742} ;
3843
3944const Settings = ( ) => {
40- // Move Supabase client initialization to state and useEffect
4145 const [ supabase , setSupabase ] = useState < any > ( null ) ;
42-
43- // Instead of using useUser, assume roleId is known (e.g. passed as a prop or hardcoded)
44- const roleId = 2 ; // Replace with actual logic to obtain the user's roleId
45-
46- const [ rolePermissions , setRolePermissions ] =
47- useState < RolePermissions | null > ( null ) ;
46+ const [ roleId , setRoleId ] = useState < number | null > ( null ) ;
47+ const [ rolePermissions , setRolePermissions ] = useState < RolePermissions | null > ( null ) ;
4848 const [ loading , setLoading ] = useState < boolean > ( true ) ;
4949
50- // Initialize Supabase client safely
50+ // Initialize Supabase client
5151 useEffect ( ( ) => {
5252 const client = createClientClientComponent ( ) ;
5353 setSupabase ( client ) ;
5454 } , [ ] ) ;
5555
56- // Helper function to check a permission
57- const hasPermission = ( permission : PermissionKey ) : boolean => {
58- return ! ! rolePermissions ?. [ permission ] ;
59- } ;
60-
56+ // Get current user's role_id by mapping auth email to codev.role_id
6157 useEffect ( ( ) => {
6258 if ( ! supabase ) return ;
6359
60+ async function fetchUserRole ( ) {
61+ try {
62+ // Get auth user
63+ const { data : { session } , error : sessionError } = await supabase . auth . getSession ( ) ;
64+
65+ if ( sessionError || ! session ?. user ?. email ) {
66+ console . error ( "Failed to get session:" , sessionError ) ;
67+ setLoading ( false ) ;
68+ return ;
69+ }
70+
71+ // Map email to codev profile to get role_id
72+ const { data : codevData , error : codevError } = await supabase
73+ . from ( "codev" )
74+ . select ( "role_id" )
75+ . eq ( "email_address" , session . user . email )
76+ . single ( ) ;
77+
78+ if ( codevError || ! codevData ) {
79+ console . error ( "Failed to fetch user role:" , codevError ) ;
80+ setLoading ( false ) ;
81+ return ;
82+ }
83+
84+ setRoleId ( codevData . role_id ) ;
85+ } catch ( err ) {
86+ console . error ( "Error fetching user role:" , err ) ;
87+ setLoading ( false ) ;
88+ }
89+ }
90+
91+ fetchUserRole ( ) ;
92+ } , [ supabase ] ) ;
93+
94+ // Fetch role permissions once we have roleId
95+ useEffect ( ( ) => {
96+ if ( ! supabase || roleId === null ) return ;
97+
6498 async function fetchRolePermissions ( ) {
6599 try {
66- // Fetch the role permissions from the "roles" table.
67100 const { data : roleData , error : roleError } = await supabase
68101 . from ( "roles" )
69102 . select (
70- "dashboard, kanban, time_tracker, interns, applicants, inhouse, clients, projects, settings, orgchart, resume, permissions, roles" ,
103+ "dashboard, kanban, time_tracker, interns, applicants, inhouse, clients, projects, settings, orgchart, resume, permissions, roles"
71104 )
72105 . eq ( "id" , roleId )
73106 . single ( ) ;
@@ -77,16 +110,23 @@ const Settings = () => {
77110 setLoading ( false ) ;
78111 return ;
79112 }
113+
80114 setRolePermissions ( roleData ) ;
81115 } catch ( err ) {
82116 console . error ( "Error fetching role permissions:" , err ) ;
83117 } finally {
84118 setLoading ( false ) ;
85119 }
86120 }
121+
87122 fetchRolePermissions ( ) ;
88123 } , [ supabase , roleId ] ) ;
89124
125+ // Helper function to check a permission
126+ const hasPermission = ( permission : PermissionKey ) : boolean => {
127+ return ! ! rolePermissions ?. [ permission ] ;
128+ } ;
129+
90130 if ( loading ) {
91131 return (
92132 < PageContainer >
@@ -95,20 +135,31 @@ const Settings = () => {
95135 ) ;
96136 }
97137
98- if ( ! rolePermissions ) {
138+ if ( ! rolePermissions || roleId === null ) {
99139 return (
100140 < PageContainer >
101141 < div className = "mx-auto p-4" > Unable to determine permissions.</ div >
102142 </ PageContainer >
103143 ) ;
104144 }
105145
106- // Filter settings cards based on role permissions.
107- // For a card whose path exists in the mapping, use its permission key;
108- // otherwise, require the general "settings" permission.
146+ // Filter settings cards based on role
109147 const filteredCards = settingsCardData . filter ( ( card ) => {
110- const permissionKey = settingsPermissionMap [ card . path ] || "settings" ;
111- return hasPermission ( permissionKey ) ;
148+ // Rule 1: Admin-only cards (News Banners, Services)
149+ // Only visible if user has role_id = 1 (Admin)
150+ if ( ADMIN_ONLY_PATHS . includes ( card . path ) ) {
151+ return roleId === 1 ;
152+ }
153+
154+ // Rule 2: Check specific permission mapping
155+ // For cards like Profile, Permissions, Roles
156+ const permissionKey = settingsPermissionMap [ card . path ] ;
157+ if ( permissionKey ) {
158+ return hasPermission ( permissionKey ) ;
159+ }
160+
161+ // Rule 3: Default fallback - require general "settings" permission
162+ return hasPermission ( "settings" ) ;
112163 } ) ;
113164
114165 return (
@@ -130,4 +181,4 @@ const Settings = () => {
130181 ) ;
131182} ;
132183
133- export default Settings ;
184+ export default Settings ;
0 commit comments