You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
387 lines
15 KiB
387 lines
15 KiB
from django.core.management.base import BaseCommand
|
|
from django.db import transaction
|
|
from apps.account.models.role import Role, ALL_PERMISSION_FIELDS
|
|
|
|
|
|
DEFAULT_ROLES = [
|
|
{
|
|
"name": "User",
|
|
"slug": "user",
|
|
"description": "Standard community member with basic profile, messaging, learning, and participation privileges.",
|
|
"is_default": True,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": False,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": False,
|
|
"can_moderate_chat": False,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": False,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": False,
|
|
"can_publish_courses": False,
|
|
"can_issue_certificates": False,
|
|
"can_grade_submissions": False,
|
|
"has_premium_lms_access": False,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": False,
|
|
"can_register_events": True,
|
|
"can_create_events": False,
|
|
"can_publish_events": False,
|
|
"can_checkin_attendees": False,
|
|
"can_export_attendee_list": False,
|
|
"can_volunteer": True,
|
|
"can_create_projects": False,
|
|
"can_manage_project_tasks": False,
|
|
"can_approve_projects": False,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": False,
|
|
"can_view_donation_reports": False,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": False,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": False,
|
|
"can_export_form_data": False,
|
|
"can_view_diplomatic_reports": False,
|
|
"can_create_diplomatic_reports": False,
|
|
"can_access_admin_panel": False,
|
|
"can_manage_users": False,
|
|
"can_ban_users": False,
|
|
"can_view_analytics": False,
|
|
}
|
|
},
|
|
{
|
|
"name": "Verified User",
|
|
"slug": "verified_user",
|
|
"description": "Verified community member with authenticated identity, video calling, and direct content publishing.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": False,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": True,
|
|
"can_moderate_chat": False,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": True,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": False,
|
|
"can_publish_courses": False,
|
|
"can_issue_certificates": False,
|
|
"can_grade_submissions": False,
|
|
"has_premium_lms_access": True,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": False,
|
|
"can_register_events": True,
|
|
"can_create_events": True,
|
|
"can_publish_events": False,
|
|
"can_checkin_attendees": False,
|
|
"can_export_attendee_list": False,
|
|
"can_volunteer": True,
|
|
"can_create_projects": False,
|
|
"can_manage_project_tasks": False,
|
|
"can_approve_projects": False,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": False,
|
|
"can_view_donation_reports": False,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": False,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": False,
|
|
"can_export_form_data": False,
|
|
"can_view_diplomatic_reports": False,
|
|
"can_create_diplomatic_reports": False,
|
|
"can_access_admin_panel": False,
|
|
"can_manage_users": False,
|
|
"can_ban_users": False,
|
|
"can_view_analytics": False,
|
|
}
|
|
},
|
|
{
|
|
"name": "Institution Admin",
|
|
"slug": "institution_admin",
|
|
"description": "Administrator of an Islamic center, university, or institution with management over courses, events, meetings, and campaigns.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": True,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": True,
|
|
"can_moderate_chat": False,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": True,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": True,
|
|
"can_publish_courses": True,
|
|
"can_issue_certificates": True,
|
|
"can_grade_submissions": True,
|
|
"has_premium_lms_access": True,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": True,
|
|
"can_register_events": True,
|
|
"can_create_events": True,
|
|
"can_publish_events": True,
|
|
"can_checkin_attendees": True,
|
|
"can_export_attendee_list": True,
|
|
"can_volunteer": True,
|
|
"can_create_projects": True,
|
|
"can_manage_project_tasks": True,
|
|
"can_approve_projects": False,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": True,
|
|
"can_view_donation_reports": True,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": False,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": True,
|
|
"can_export_form_data": True,
|
|
"can_view_diplomatic_reports": True,
|
|
"can_create_diplomatic_reports": False,
|
|
"can_access_admin_panel": False,
|
|
"can_manage_users": False,
|
|
"can_ban_users": False,
|
|
"can_view_analytics": False,
|
|
}
|
|
},
|
|
{
|
|
"name": "Institution Owner",
|
|
"slug": "institution_owner",
|
|
"description": "Owner / Primary Representative of an institution with full oversight over institutional projects, campaigns, and diplomacy.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": True,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": True,
|
|
"can_moderate_chat": False,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": True,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": True,
|
|
"can_publish_courses": True,
|
|
"can_issue_certificates": True,
|
|
"can_grade_submissions": True,
|
|
"has_premium_lms_access": True,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": True,
|
|
"can_register_events": True,
|
|
"can_create_events": True,
|
|
"can_publish_events": True,
|
|
"can_checkin_attendees": True,
|
|
"can_export_attendee_list": True,
|
|
"can_volunteer": True,
|
|
"can_create_projects": True,
|
|
"can_manage_project_tasks": True,
|
|
"can_approve_projects": True,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": True,
|
|
"can_view_donation_reports": True,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": False,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": True,
|
|
"can_export_form_data": True,
|
|
"can_view_diplomatic_reports": True,
|
|
"can_create_diplomatic_reports": True,
|
|
"can_access_admin_panel": False,
|
|
"can_manage_users": False,
|
|
"can_ban_users": False,
|
|
"can_view_analytics": False,
|
|
}
|
|
},
|
|
{
|
|
"name": "Content Moderator",
|
|
"slug": "content_moderator",
|
|
"description": "Community moderator responsible for chat safety, content review, and ticket management.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": False,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": False,
|
|
"can_moderate_chat": True,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": True,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": False,
|
|
"can_publish_courses": False,
|
|
"can_issue_certificates": False,
|
|
"can_grade_submissions": False,
|
|
"has_premium_lms_access": False,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": False,
|
|
"can_register_events": True,
|
|
"can_create_events": False,
|
|
"can_publish_events": False,
|
|
"can_checkin_attendees": False,
|
|
"can_export_attendee_list": False,
|
|
"can_volunteer": True,
|
|
"can_create_projects": False,
|
|
"can_manage_project_tasks": False,
|
|
"can_approve_projects": False,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": False,
|
|
"can_view_donation_reports": False,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": True,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": False,
|
|
"can_export_form_data": False,
|
|
"can_view_diplomatic_reports": False,
|
|
"can_create_diplomatic_reports": False,
|
|
"can_access_admin_panel": True,
|
|
"can_manage_users": False,
|
|
"can_ban_users": False,
|
|
"can_view_analytics": False,
|
|
}
|
|
},
|
|
{
|
|
"name": "Regional Admin",
|
|
"slug": "regional_admin",
|
|
"description": "Regional supervisor with authority over regional institutions, user accounts, and community analytics.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {
|
|
"is_searchable": True,
|
|
"can_submit_verification": True,
|
|
"can_view_full_profiles": True,
|
|
"can_manage_institutions": True,
|
|
"can_send_direct_messages": True,
|
|
"can_create_group_chats": True,
|
|
"can_start_video_calls": True,
|
|
"can_moderate_chat": True,
|
|
"is_chat_muted": False,
|
|
"can_create_posts": True,
|
|
"can_publish_posts_directly": True,
|
|
"can_edit_own_posts": True,
|
|
"can_delete_own_posts": True,
|
|
"can_comment": True,
|
|
"can_enroll_courses": True,
|
|
"can_create_courses": True,
|
|
"can_publish_courses": True,
|
|
"can_issue_certificates": True,
|
|
"can_grade_submissions": True,
|
|
"has_premium_lms_access": True,
|
|
"can_request_meetings": True,
|
|
"can_accept_meetings": True,
|
|
"can_register_events": True,
|
|
"can_create_events": True,
|
|
"can_publish_events": True,
|
|
"can_checkin_attendees": True,
|
|
"can_export_attendee_list": True,
|
|
"can_volunteer": True,
|
|
"can_create_projects": True,
|
|
"can_manage_project_tasks": True,
|
|
"can_approve_projects": True,
|
|
"can_make_donations": True,
|
|
"can_create_donation_campaigns": True,
|
|
"can_view_donation_reports": True,
|
|
"can_create_tickets": True,
|
|
"can_reply_tickets": True,
|
|
"can_manage_tickets": True,
|
|
"can_submit_forms": True,
|
|
"can_create_forms": True,
|
|
"can_export_form_data": True,
|
|
"can_view_diplomatic_reports": True,
|
|
"can_create_diplomatic_reports": True,
|
|
"can_access_admin_panel": True,
|
|
"can_manage_users": True,
|
|
"can_ban_users": True,
|
|
"can_view_analytics": True,
|
|
}
|
|
},
|
|
{
|
|
"name": "Super Administrator",
|
|
"slug": "super_admin",
|
|
"description": "Master administrative role with all permissions, total access control, and full platform authority.",
|
|
"is_default": False,
|
|
"is_system": True,
|
|
"permissions": {perm: (perm != "is_chat_muted") for perm in ALL_PERMISSION_FIELDS}
|
|
},
|
|
]
|
|
|
|
|
|
class Command(BaseCommand):
|
|
help = "Seed the 7 default configurable system roles with their exact permission matrix"
|
|
|
|
@transaction.atomic
|
|
def handle(self, *args, **options):
|
|
self.stdout.write("Seeding default system roles...")
|
|
created_count = 0
|
|
updated_count = 0
|
|
|
|
for role_data in DEFAULT_ROLES:
|
|
perms = role_data.pop("permissions")
|
|
role, created = Role.objects.get_or_create(
|
|
slug=role_data["slug"],
|
|
defaults={
|
|
"name": role_data["name"],
|
|
"description": role_data["description"],
|
|
"is_default": role_data["is_default"],
|
|
"is_system": role_data["is_system"],
|
|
**perms
|
|
}
|
|
)
|
|
|
|
if not created:
|
|
# Update role configuration if existing
|
|
role.name = role_data["name"]
|
|
role.description = role_data["description"]
|
|
role.is_default = role_data["is_default"]
|
|
role.is_system = role_data["is_system"]
|
|
for perm, val in perms.items():
|
|
setattr(role, perm, val)
|
|
role.save()
|
|
updated_count += 1
|
|
self.stdout.write(self.style.SUCCESS(f" [✓] Updated role: {role.name} ({role.slug})"))
|
|
else:
|
|
created_count += 1
|
|
self.stdout.write(self.style.SUCCESS(f" [+] Created role: {role.name} ({role.slug})"))
|
|
|
|
self.stdout.write(self.style.SUCCESS(
|
|
f"Successfully finished seeding roles: {created_count} created, {updated_count} updated."
|
|
))
|