Skip to content

User Management

Ilyes BEN BRIK edited this page Jul 18, 2026 · 1 revision

User Management

Roles

Role Description Permissions
Admin Full control Everything β€” users, locations, writers, genres, publishers, backup, settings
User Regular user Add/edit/delete books, lend, scan, view reports, update own profile
Viewer Read-only View books, reports, locations (cannot add, edit, or delete anything)

Creating Users (Admin)

  1. Go to πŸ‘₯ Users β†’ βž• Add User
  2. Fill in:
    • Full Name
    • Username (unique)
    • Email (unique)
    • Password (min 10 chars, uppercase + lowercase + number)
    • Role (User, Admin, or Viewer)
  3. Click Create User

Managing Users (Admin)

Action How
Disable a user Click Disable β€” prevents login
Enable a user Click Enable β€” restores access
Delete a user Click Delete β€” permanent, cannot delete yourself

Registration

By default, anyone can register at the login page (rate-limited to 3 per hour per IP). New registrations get the User role.

Disabling Public Registration

To restrict registration to admin-only, edit backend/routes/api.php:

// Change:
$router->post('/api/auth/register', [AuthController::class, 'register']);
// To:
$router->post('/api/auth/register', [AuthController::class, 'register'], [AdminMiddleware::class]);

Permission Matrix

Feature Admin User Viewer
View books & reports βœ… βœ… βœ…
Add/edit/delete books βœ… βœ… ❌
Scan books (camera) βœ… βœ… ❌
Lend/return books βœ… βœ… ❌
Manage writers βœ… ❌ ❌
Manage genres βœ… ❌ ❌
Manage publishers βœ… ❌ ❌
Manage locations βœ… ❌ ❌
Manage users βœ… ❌ ❌
Backup/restore βœ… ❌ ❌
Update own profile βœ… βœ… βœ…
Change own password βœ… βœ… βœ…

Next: Reports & Export

Clone this wiki locally