Go to most recent revision | Blame | Compare with Previous | Last modification | View Log | RSS feed
-- Migration: Demo partner access (2026-09-25)---- Lets an admin tag any partner to a Sales person purely so they can open that partner's-- dashboard / Franchise App for a demo. The binding lives ONLY in cs.demo_partner_access and is-- read ONLY at the partner-view entry points (fofo Partner access dropdown, login-as-partner-readonly,-- /mobileapp token; web /getPartners, /getPartnersList, /impersonate). The position mappings-- (cs.position / cs.partner_position and CsService.getAuthUser*Mapping) are NOT touched, so no-- performance, target, report or cron figure changes.---- A grant is active while revoked_at IS NULL. Revoke stamps revoked_at/revoked_by (history kept);-- re-granting after a revoke inserts a new row.CREATE TABLE IF NOT EXISTS cs.demo_partner_access (id INT NOT NULL AUTO_INCREMENT,auth_user_id INT NOT NULL,fofo_id INT NOT NULL,created_by INT NOT NULL,created_at DATETIME NOT NULL,revoked_by INT NULL,revoked_at DATETIME NULL,PRIMARY KEY (id),KEY idx_demo_partner_access_auth_user (auth_user_id, revoked_at),KEY idx_demo_partner_access_fofo (fofo_id)) ENGINE = InnoDB DEFAULT CHARSET = utf8;-- Menu "Demo Partner Access" under Admin Control (id=176), next to "Partner access" (92).-- Deliberately NOT copied from menu 92: that one is visible to Sales, who must not grant to themselves.INSERT INTO auth.menu (display_text, description, parent_menu_id, sequence, action_class, icon_class)SELECT 'Demo Partner Access','Grant / revoke demo dashboard access to partners for Sales team',176,COALESCE((SELECT MAX(sequence) FROM auth.menu WHERE parent_menu_id = 176), 0) + 1,'demo-partner-access',NULLWHERE NOT EXISTS (SELECT 1 FROM auth.menu WHERE action_class = 'demo-partner-access');-- Who sees it (same rule as the sidebar, AdminUser.adminPanel, and the server guard DemoPartnerAccessService.canManage):-- AdminUser.ALL_MENU_EMAILS and every L5 position holder see all menus anyway; beyond them, the-- menu_category rows below. escalation_type here is the EscalationType ORDINAL ('3' = L4), the same-- Business Intelligence mapping 70 other menus use. Add rows to widen who can manage grants.INSERT INTO auth.menu_category (menu_id, category_id, escalation_type)SELECT m.id, 19, '3'FROM auth.menu mWHERE m.action_class = 'demo-partner-access'AND NOT EXISTS (SELECT 1 FROM auth.menu_category mc WHERE mc.menu_id = m.id AND mc.category_id = 19 AND mc.escalation_type = '3');-- Verify-- SELECT * FROM auth.menu WHERE action_class = 'demo-partner-access';-- SELECT mc.* FROM auth.menu_category mc JOIN auth.menu m ON m.id = mc.menu_id WHERE m.action_class = 'demo-partner-access';-- Rollback-- DELETE mc FROM auth.menu_category mc JOIN auth.menu m ON m.id = mc.menu_id WHERE m.action_class = 'demo-partner-access';-- DELETE FROM auth.menu WHERE action_class = 'demo-partner-access';-- DROP TABLE cs.demo_partner_access;