Fase 2: read-only user role with per-category view toggles

Adds a third account type 'user' alongside super/admin: no create/edit/delete
rights on qr codes, view access to dynamic/static lists gated per-account by
two admin-controlled toggles (can_view_static, can_view_dynamic), and always
full visibility into the dashboard/reports regardless of those toggles.

- New columns can_view_static/can_view_dynamic on users (migrations/003)
- Users class + form_users.php: 'user' type option with the two toggles
- Access control: dynamic_qrcode.php/static_qrcode.php/bulk_action.php reject
  all mutations for type=user; dynamic_qrcodes.php/static_qrcodes.php enforce
  the view toggle and show all codes (no owner scoping, since 'user' owns none)
- Sidebar and list tables hide add/edit/delete/bulk UI for the read-only role
- index.php dashboard stats are unscoped for both 'super' and 'user'

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-08 16:37:25 +02:00
parent feb5380b28
commit a1ab16d54c
15 changed files with 163 additions and 15 deletions
+12 -3
View File
@@ -1,4 +1,6 @@
<?php $is_readonly_user = $_SESSION['type'] === 'user'; ?>
<div class="row">
<?php if (!$is_readonly_user): ?>
<div class="col-12" id="bulk-action-div" style="display: none;">
<div id="err-msg"></div>
<div class="bulk-action-wrapper">
@@ -21,13 +23,16 @@
</form>
</div>
</div>
<?php endif; ?>
<div class="col-12">
<div class="card">
<div class="card-body table-responsive p-0">
<table class="table table-striped table-bordered">
<thead>
<tr>
<?php if (!$is_readonly_user): ?>
<th><input type="checkbox" name="bulk-select" value="1"></th>
<?php endif; ?>
<th>ID</th>
<th>Owner</th>
<th>Filename</th>
@@ -42,7 +47,9 @@
<tbody>
<?php foreach ($rows as $row): ?>
<tr>
<?php if (!$is_readonly_user): ?>
<td><input type="checkbox" name="action[]" value="<?=$row['id']?>" onchange="updateBulkActionVisibility()"></td>
<?php endif; ?>
<td><?php echo $row['id']; ?></td>
<td>
<?php
@@ -68,10 +75,10 @@
<td><?php echo htmlspecialchars($row['scan']); ?></td>
<td><?php echo htmlspecialchars($row['state']); ?></td>
<td>
<?php if (!$is_readonly_user): ?>
<!-- EDIT -->
<a href="dynamic_qrcode.php?edit=true&id=<?php echo $row['id']; ?>" class="btn btn-primary"><i class="fas fa-edit"></i></a>
<!-- DELETE -->
<a
class="btn btn-danger delete_btn"
@@ -79,7 +86,7 @@
data-target="#delete-modal"
data-del_id="<?php echo $row["id"];?>"
><i class="fas fa-trash"></i></a>
<?php endif; ?>
<!-- DOWNLOAD -->
<a href="<?php echo SAVED_QRCODE_FOLDER.htmlspecialchars($row['qrcode']); ?>" class="btn btn-primary" download><i class="fa fa-download"></i></a>
</td>
@@ -97,6 +104,7 @@
</div><!-- /.col -->
</div><!-- /.row -->
<?php if (!$is_readonly_user): ?>
<!-- Delete Confirmation Modal -->
<div class="modal fade" id="delete-modal" role="dialog">
<div class="modal-dialog">
@@ -122,6 +130,7 @@
</div>
</div>
<!-- /.Delete Confirmation Modal -->
<?php endif; ?>
<script>
const deleteButtons = document.querySelectorAll('.delete_btn');