Files
QRForge-selfhosted/src/forms/form_users.php
T
dillard 52c9f65c61 Fase 2: read-only user role with per-category view toggles
Adds a third account type 'user' alongside super/admin: no create/edit/delete
rights on qr codes, view access to dynamic/static lists gated per-account by
two admin-controlled toggles (can_view_static, can_view_dynamic), and always
full visibility into the dashboard/reports regardless of those toggles.

- New columns can_view_static/can_view_dynamic on users (migrations/003)
- Users class + form_users.php: 'user' type option with the two toggles
- Access control: dynamic_qrcode.php/static_qrcode.php/bulk_action.php reject
  all mutations for type=user; dynamic_qrcodes.php/static_qrcodes.php enforce
  the view toggle and show all codes (no owner scoping, since 'user' owns none)
- Sidebar and list tables hide add/edit/delete/bulk UI for the read-only role
- index.php dashboard stats are unscoped for both 'super' and 'user'
2026-07-08 16:37:25 +02:00

86 lines
3.8 KiB
PHP

<fieldset>
<div class="col-sm-4">
<div class="form-group">
<label for="username">Username *</label>
<div class="input-group">
<div class="input-group-prepend">
<span class="input-group-text"><i class="fa fa-user"></i></span>
</div>
<input type="text" name="username" placeholder="Username" class="form-control" required="required" value="<?php echo ($edit) ? $user['username'] : ''; ?>" autocomplete="off">
</div>
</div>
</div>
<div class="col-sm-4">
<div class="form-group">
<label for="password">Password *</label>
<div class="input-group">
<div class="input-group-prepend">
<span class="input-group-text"><i class="fa fa-lock"></i></span>
</div>
<input type="password" name="password" placeholder="<?php echo ($edit) ? 'Leave blank to keep current password' : 'Password'; ?>" class="form-control" <?php echo ($edit) ? '' : 'required="required"'; ?> minlength="10" autocomplete="off">
</div>
</div>
</div>
<div class="col-sm-4">
<label for="user-type">User type *</label>
<div class="form-group">
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="super" required="required" <?php echo ($edit && $user['type'] =='super') ? "checked": "" ; ?>/> Super admin</label>
</div>
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="admin" required="required" <?php echo ($edit && $user['type'] =='admin') ? "checked": "" ; ?>/> Admin</label>
</div>
<div class="radio">
<label class="radio">
<input type="radio" name="type" value="user" required="required" id="type-user" <?php echo ($edit && $user['type'] =='user') ? "checked": "" ; ?>/> User (read-only)</label>
</div>
</div>
</div>
<div class="col-sm-12 mt-2" id="user-view-toggles">
<label>Zichtbaarheid voor 'User'-rol</label>
<div class="form-group">
<div class="icheck-primary d-inline-block mr-4">
<input type="checkbox" name="can_view_static" id="can_view_static" value="1" <?php echo ($edit && !empty($user['can_view_static'])) ? "checked": "" ; ?>>
<label for="can_view_static">Mag statische QR-codes bekijken</label>
</div>
<div class="icheck-primary d-inline-block">
<input type="checkbox" name="can_view_dynamic" id="can_view_dynamic" value="1" <?php echo ($edit && !empty($user['can_view_dynamic'])) ? "checked": "" ; ?>>
<label for="can_view_dynamic">Mag dynamische QR-codes bekijken</label>
</div>
<small class="form-text text-muted">Alleen van toepassing op het type 'User'. Reports/statistieken zijn voor 'User' altijd zichtbaar.</small>
</div>
</div>
<script>
(function () {
var typeRadios = document.querySelectorAll('input[name="type"]');
var toggles = document.getElementById('user-view-toggles');
function updateToggleVisibility() {
var userSelected = document.getElementById('type-user').checked;
toggles.style.display = userSelected ? '' : 'none';
}
typeRadios.forEach(function (radio) {
radio.addEventListener('change', updateToggleVisibility);
});
updateToggleVisibility();
})();
</script>
<?php if($edit) { ?>
<input type="hidden" name="id" value="<?php echo $user['id'];?>"/>
<input type="hidden" name="edit" value="true"/>
<?php } ?>
</fieldset>