import { api } from '../api.js'; import { showToast } from '../components/toast.js'; import { esc, isPlatformAdmin } from '../utils.js'; import { t } from '../i18n.js'; import { openAddUserModal } from '../components/workspace-members-add-user-modal.js'; import { openManageWorkspacesModal } from '../components/admin-user-workspaces-modal.js'; import { openCreateOrgModal } from '../components/admin-create-org-modal.js'; import { openTypeToConfirmModal } from '../components/type-to-confirm-modal.js'; // Reuse the members view's server-error -> friendly-string mapper (handles the // 409 duplicate-email / weak-password / invalid-email cases) so we don't fork a // second mapper. import { mapMutationError } from './workspace-members.js'; const headers = () => ({ Authorization: `Bearer ${localStorage.getItem('token')}`, 'Content-Type': 'application/json' }); const API = (url, opts = {}) => fetch('/api' + url, { headers: headers(), ...opts }).then(r => r.json()); // #14: the platform user-management dropdown manages users.role (the // PLATFORM-level role) only - workspace/org roles are managed in the members // views. Options are the current model; the legacy 'admin'/'superadmin' strings // were normalized away. #13 adds 'platform_operator' (cross-org staff). const PLATFORM_ROLE_OPTIONS = ['user', 'platform_operator', 'platform_admin']; // Platform staff have cross-org access (no single workspace), so the Workspace // column shows read-only "Platform (all)" for them. Note utils.isPlatformAdmin // only covers admin/superadmin; operators are staff here too. function isPlatformStaffRole(role) { return role === 'platform_admin' || role === 'superadmin' || role === 'platform_operator'; } // Short summary of a user's workspace membership for the Users-table cell. // Platform staff have cross-org access (not per-workspace membership) -> "Platform // (all)". Otherwise: Unassigned (0), the workspace name (1), or "N workspaces". function workspaceSummary(u) { if (isPlatformStaffRole(u.role)) return t('admin.workspace.platform_all'); const count = u.workspace_count || 0; if (count === 0) return t('admin.workspace.unassigned'); if (count === 1) return esc(u.workspace_name || ''); return t('admin.workspace.multi', { n: count }); } // Workspace cell: a summary + a "Manage" button that opens the full membership // modal (add/remove workspaces, set per-workspace role). Manage is offered for // everyone, including staff (you can grant them explicit memberships too). function workspaceCell(u) { return `
${t('admin.access_denied_desc')}
${t('common.loading')}
${t('admin.orgs.desc')}
${t('common.loading')}
${t('admin.branding.desc')}
${t('common.loading')}
${t('common.loading')}
${t('common.loading')}
${esc(err.message || 'Failed to load organizations')}
`; return; } if (!orgs.length) { el.innerHTML = `${t('admin.orgs.empty')}
`; return; } el.innerHTML = orgs.map(o => { const wsRows = (o.workspaces || []).map(w => `${esc(e.message || 'Failed to load')}
`; return; } const v = (x) => esc(x == null ? '' : x); el.innerHTML = `| ${t('admin.col.user')} | ${t('admin.col.auth')} | ${t('admin.col.last_login')} | ${t('admin.col.role')} | ${t('admin.col.plan')} | ${t('admin.col.workspace')} | ${t('admin.col.actions')} |
|---|---|---|---|---|---|---|
${u.name || u.email} ${u.email} |
${u.auth_provider} | ${u.last_login ? new Date(u.last_login * 1000).toLocaleString() : t('common.never')} | ${workspaceCell(u)} | ${u.auth_provider === 'local' && u.id !== currentUser.id ? `` : ''} ${!isPlatformAdmin(u) ? `` : `${t('admin.owner')}`} |
${t('admin.total_users', { n: users.length })}
`; el.querySelectorAll('[data-role-user]').forEach(select => { select.onchange = async () => { try { await API(`/auth/users/${select.dataset.roleUser}/role`, { method: 'PUT', body: JSON.stringify({ role: select.value }) }); showToast(t('admin.toast.role_updated'), 'success'); } catch (err) { showToast(err.message, 'error'); loadUsers(); } }; }); el.querySelectorAll('[data-plan-user]').forEach(select => { select.onchange = async () => { try { await API('/subscription/assign', { method: 'POST', body: JSON.stringify({ user_id: select.dataset.planUser, plan_id: select.value }) }); showToast(t('admin.toast.plan_updated'), 'success'); } catch (err) { showToast(err.message, 'error'); loadUsers(); } }; }); // Manage workspaces: open the per-user membership modal (add/remove // workspaces, set per-workspace role). Refresh the table on close only if // something changed (the modal calls onClose then). el.querySelectorAll('[data-ws-manage]').forEach(btn => { btn.onclick = () => { const u = users.find(x => x.id === btn.dataset.wsManage); if (!u) return; openManageWorkspacesModal(u, { onClose: () => loadUsers() }); }; }); // Reset password handlers el.querySelectorAll('[data-reset-pw-user]').forEach(btn => { btn.onclick = async () => { const email = btn.dataset.userEmail; const pw = prompt(t('admin.prompt_reset_password', { email })); if (pw === null) return; if (pw.length < 8) { showToast(t('admin.toast.password_min_8'), 'error'); return; } try { await api.resetUserPassword(btn.dataset.resetPwUser, pw); showToast(t('admin.toast.password_reset'), 'success'); } catch (err) { showToast(err.message, 'error'); } }; }); el.querySelectorAll('[data-delete-user]').forEach(btn => { let confirming = false; btn.onclick = async () => { if (confirming) { try { await api.deleteUser(btn.dataset.deleteUser); showToast(t('admin.toast.user_removed'), 'success'); loadUsers(); } catch (err) { showToast(err.message, 'error'); } return; } confirming = true; btn.textContent = t('admin.confirm'); btn.style.background = 'var(--danger)'; btn.style.color = 'white'; setTimeout(() => { confirming = false; btn.textContent = t('admin.remove'); btn.style.background = ''; btn.style.color = ''; }, 3000); }; }); } catch (err) { el.innerHTML = `${esc(err.message)}
`; } } async function loadPlans() { const el = document.getElementById('plansTable'); try { const plans = await fetch('/api/subscription/plans').then(r => r.json()); el.innerHTML = `| ${t('admin.col.plan')} | ${t('admin.col.devices')} | ${t('admin.col.storage')} | ${t('admin.col.monthly')} | ${t('admin.col.yearly')} |
|---|---|---|---|---|
| ${p.display_name} | ${p.max_devices === -1 ? t('admin.unlimited') : p.max_devices} | ${p.max_storage_mb === -1 ? t('admin.unlimited') : p.max_storage_mb >= 1024 ? (p.max_storage_mb/1024)+'GB' : p.max_storage_mb+'MB'} | ${p.price_monthly > 0 ? '$'+p.price_monthly : t('admin.free')} | ${p.price_yearly > 0 ? '$'+p.price_yearly : '-'} |
${esc(err.message)}
`; } } async function loadSystem() { const el = document.getElementById('systemInfo'); try { const version = await fetch('/api/version').then(r => r.json()); const token = localStorage.getItem('token'); el.innerHTML = `${esc(err.message)}
`; } } export function cleanup() {}