Files
sure/app/views/admin/users/index.html.erb
Juan José Mata 02af8463f6 Administer invitations in /admin/users (#1185)
* Add invited users with delete button to admin users page

Shows pending invitations per family below active users in /admin/users/.
Each invitation row has a red Delete button aligned with the role column.
Alt/option-clicking any Delete button changes all invitation button labels
to "Delete All" and destroys all pending invitations for that family.

- Add admin routes: DELETE /admin/invitations/:id and DELETE /admin/families/:id/invitations
- Add Admin::InvitationsController with destroy and destroy_all actions
- Load pending invitations grouped by family in users controller index
- Render invitation rows in a dashed-border tbody below active user rows
- Add admin-invitation-delete Stimulus controller for alt-click behavior
- Add i18n strings for invitation UI and flash messages

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Fix destroy_all using params[:id] from member route

The member route /admin/families/:id/invitations sets params[:id],
not params[:family_id], so Family.find was always receiving nil.

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Fix translation key in destroy_all to match locale

t(".success_all") looked up a nonexistent key; the locale defines
admin.invitations.destroy_all.success, so t(".success") is correct.

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Scope bulk delete to pending invitations and allow re-inviting emails

- destroy_all now uses family.invitations.pending.destroy_all so accepted
  and expired invitation history is preserved
- Replace blanket email uniqueness validation with a custom check scoped
  to pending invitations only, so the same email can be invited again
  after an invitation is deleted or expires

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Drop unconditional unique DB index on invitations(email, family_id)

The model-level uniqueness check was already scoped to pending
invitations, but the blanket unique index on (email, family_id)
still caused ActiveRecord::RecordNotUnique when re-inviting an
email that had any historical invitation record in the same family
(e.g. after an accepted invite or after an account deletion).

Replace it with no DB-level unique constraint — the
no_duplicate_pending_invitation_in_family model validation is the
sole enforcer and correctly scopes uniqueness to pending rows only.

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Replace blanket unique index with partial unique index on pending invitations

Instead of dropping the DB-level uniqueness constraint entirely, replace
the unconditional unique index on (email, family_id) with a partial unique
index scoped to WHERE accepted_at IS NULL. This enforces the invariant at
the DB layer (no two non-accepted invitations for the same email in a
family) while allowing re-invites once a prior invitation has been accepted.

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

* Fix migration version and make remove_index reversible

- Change Migration[8.0] to Migration[7.2] to match the rest of the codebase
- Pass column names to remove_index so Rails can reconstruct the old index on rollback

https://claude.ai/code/session_01F8WaH5TmtdUWwhHnVoQ6Gm

---------

Signed-off-by: Juan José Mata <juanjo.mata@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-03-14 11:32:33 +01:00

220 lines
12 KiB
Plaintext

<%= content_for :page_title, t(".title") %>
<div class="bg-container rounded-xl shadow-border-xs p-4">
<div class="mb-6">
<p class="text-sm text-secondary"><%= t(".description") %></p>
</div>
<!-- Filters -->
<div class="mb-6">
<%= form_with url: admin_users_path, method: :get, class: "flex gap-4 items-end flex-wrap" do |f| %>
<div class="w-full md:w-auto">
<%= f.label :role, t(".filters.role"), class: "block text-sm font-medium text-primary mb-1" %>
<%= f.select :role,
options_for_select(
[[t(".filters.role_all"), ""], [t(".roles.guest"), "guest"], [t(".roles.member", default: "Member"), "member"], [t(".roles.admin"), "admin"], [t(".roles.super_admin"), "super_admin"]],
params[:role]
),
{},
class: "rounded-lg border border-primary px-3 py-2 text-sm bg-container-inset text-primary w-full" %>
</div>
<div class="w-full md:w-auto">
<%= f.label :trial_status, t(".filters.trial_status"), class: "block text-sm font-medium text-primary mb-1" %>
<%= f.select :trial_status,
options_for_select(
[[t(".filters.trial_all"), ""], [t(".filters.trial_expiring_soon"), "expiring_soon"], [t(".filters.trial_trialing"), "trialing"]],
params[:trial_status]
),
{},
class: "rounded-lg border border-primary px-3 py-2 text-sm bg-container-inset text-primary w-full" %>
</div>
<%= render DS::Button.new(variant: :primary, size: :md, type: "submit", text: t(".filters.submit"), class: "md:w-auto w-full justify-center") %>
<% end %>
</div>
<!-- Summary: trials expiring in next 7 days -->
<div class="grid grid-cols-1 md:grid-cols-4 gap-4 mb-6">
<div class="bg-container-inset rounded-lg p-4">
<div class="flex items-center gap-2 mb-2">
<%= icon "calendar-clock", class: "w-5 h-5 text-secondary" %>
<p class="text-xs font-medium text-secondary uppercase"><%= t(".summary.trials_expiring_7_days") %></p>
</div>
<p class="text-2xl font-semibold text-primary"><%= @trials_expiring_in_7_days %></p>
</div>
</div>
<!-- Families/Groups & Users -->
<div>
<h2 class="text-lg font-semibold text-primary mb-3"><%= t(".section_title") %></h2>
<% if @families_with_users.any? %>
<div class="space-y-4">
<% @families_with_users.each do |family, users| %>
<% pending_invitations = @invitations_by_family[family.id] || [] %>
<details class="bg-container-inset rounded-lg overflow-hidden group"
data-controller="admin-invitation-delete"
data-admin-invitation-delete-delete-all-label-value="<%= t('.invitations.delete_all') %>">
<summary class="flex items-center justify-between gap-4 px-4 py-3 cursor-pointer select-none hover:bg-surface-hover">
<div class="flex items-center gap-3">
<%= icon "users", class: "w-5 h-5 text-secondary shrink-0" %>
<div>
<p class="font-semibold text-primary"><%= family.name.presence || t(".unnamed_family") %></p>
<p class="text-xs text-secondary">
<%= t(".family_summary",
members: users.size,
accounts: number_with_delimiter(@accounts_count_by_family[family.id] || 0),
transactions: number_with_delimiter(@entries_count_by_family[family.id] || 0)) %>
</p>
</div>
</div>
<div class="flex items-center gap-4 shrink-0">
<% sub = family.subscription %>
<% if sub&.trialing? %>
<span class="text-xs text-secondary">
<%= t(".table.trial_ends_at") %>: <%= sub.trial_ends_at&.to_fs(:long) || t(".not_available") %>
</span>
<% elsif sub %>
<span class="inline-flex items-center px-2 py-0.5 rounded text-xs font-medium
<%= sub.active? ? 'bg-green-100 text-green-800' : 'bg-surface text-secondary' %>">
<%= sub.status.humanize %>
</span>
<% else %>
<span class="text-xs text-secondary"><%= t(".no_subscription") %></span>
<% end %>
<%= icon "chevron-down", class: "w-4 h-4 text-secondary transition-transform group-open:rotate-180" %>
</div>
</summary>
<div class="border-t border-primary">
<table class="w-full">
<thead class="bg-surface-default border-b border-primary">
<tr>
<th class="px-4 py-2 text-left text-xs font-medium text-secondary uppercase"><%= t(".table.user") %></th>
<th class="px-4 py-2 text-left text-xs font-medium text-secondary uppercase"><%= t(".table.last_login") %></th>
<th class="px-4 py-2 text-right text-xs font-medium text-secondary uppercase"><%= t(".table.session_count") %></th>
<th class="px-4 py-2 text-right text-xs font-medium text-secondary uppercase"><%= t(".table.role") %></th>
</tr>
</thead>
<tbody class="divide-y divide-primary">
<% users.each do |user| %>
<tr>
<td class="px-4 py-3">
<div class="flex items-center gap-3">
<div class="w-8 h-8 rounded-full bg-surface flex items-center justify-center shrink-0">
<span class="text-sm font-medium text-primary"><%= user.initials %></span>
</div>
<div>
<p class="font-medium text-primary"><%= user.display_name %></p>
<p class="text-sm text-secondary"><%= user.email %></p>
</div>
</div>
</td>
<td class="px-4 py-3 text-sm text-primary whitespace-nowrap">
<%= @last_login_by_user[user.id]&.to_fs(:long) || t(".table.never") %>
</td>
<td class="px-4 py-3 text-sm text-primary text-right whitespace-nowrap">
<%= number_with_delimiter(@sessions_count_by_user[user.id] || 0) %>
</td>
<td class="px-4 py-3 text-right">
<% if user.id == Current.user.id %>
<span class="text-sm text-secondary"><%= t(".you") %></span>
<% else %>
<%= form_with model: [:admin, user], method: :patch, class: "flex items-center justify-end gap-2", data: { controller: "auto-submit-form" } do |form| %>
<%= form.select :role,
options_for_select([
[t(".roles.guest"), "guest"],
[t(".roles.member", default: "Member"), "member"],
[t(".roles.admin"), "admin"],
[t(".roles.super_admin"), "super_admin"]
], user.role),
{},
class: "text-sm rounded-lg border border-primary bg-container text-primary px-2 py-1",
data: { auto_submit_form_target: "auto" } %>
<% end %>
<% end %>
</td>
</tr>
<% end %>
</tbody>
<% if pending_invitations.any? %>
<tbody class="divide-y divide-primary border-t border-dashed border-primary">
<% pending_invitations.each do |invitation| %>
<tr class="bg-red-50/30 dark:bg-red-950/20">
<td class="px-4 py-3">
<div class="flex items-center gap-3">
<%= icon "mail", class: "w-5 h-5 text-secondary shrink-0" %>
<div>
<p class="font-medium text-secondary italic"><%= invitation.email %></p>
<p class="text-xs text-secondary"><%= t(".invitations.pending_label") %></p>
</div>
</div>
</td>
<td class="px-4 py-3 text-sm text-secondary whitespace-nowrap">
<%= t(".invitations.expires", date: invitation.expires_at.to_fs(:long)) %>
</td>
<td class="px-4 py-3 text-sm text-secondary text-right whitespace-nowrap">
</td>
<td class="px-4 py-3 text-right">
<%= form_with url: admin_invitation_path(invitation), method: :delete, class: "inline" do |f| %>
<button type="submit"
data-admin-invitation-delete-target="button"
data-action="click->admin-invitation-delete#handleClick"
class="text-sm text-red-600 hover:text-red-800 border border-red-300 rounded-lg px-2 py-1 hover:bg-red-50 transition-colors">
<%= t(".invitations.delete") %>
</button>
<% end %>
</td>
</tr>
<% end %>
</tbody>
<% end %>
</table>
<% if pending_invitations.any? %>
<%= form_with url: invitations_admin_family_path(family), method: :delete,
data: { admin_invitation_delete_target: "destroyAllForm" },
class: "hidden" do |f| %>
<% end %>
<% end %>
</div>
</details>
<% end %>
</div>
<% else %>
<div class="bg-container-inset rounded-lg p-8 text-center">
<%= icon "users", class: "w-12 h-12 mx-auto text-secondary mb-3" %>
<p class="text-secondary"><%= t(".no_users") %></p>
</div>
<% end %>
</div>
<%= settings_section title: t(".role_descriptions_title"), collapsible: true, open: true do %>
<div class="space-y-3 text-sm">
<div class="flex items-start gap-3">
<span class="inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-surface text-primary shrink-0">
<%= t(".roles.guest") %>
</span>
<p class="text-secondary"><%= t(".role_descriptions.guest") %></p>
</div>
<div class="flex items-start gap-3">
<span class="inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-surface text-primary shrink-0">
<%= t(".roles.member", default: "Member") %>
</span>
<p class="text-secondary"><%= t(".role_descriptions.member", default: "Basic user access. Can manage their own accounts, transactions, and settings.") %></p>
</div>
<div class="flex items-start gap-3">
<span class="inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-surface text-primary shrink-0">
<%= t(".roles.admin") %>
</span>
<p class="text-secondary"><%= t(".role_descriptions.admin") %></p>
</div>
<div class="flex items-start gap-3">
<span class="inline-flex items-center px-2 py-0.5 rounded text-xs font-medium bg-green-100 text-green-800 shrink-0">
<%= t(".roles.super_admin") %>
</span>
<p class="text-secondary"><%= t(".role_descriptions.super_admin") %></p>
</div>
</div>
<% end %>
</div>