mirror of
https://github.com/we-promise/sure.git
synced 2026-09-04 06:11:12 +00:00
* feat: add safe admin user removal * fix: address user removal review findings * fix: close remaining user removal review gaps * fix: handle deleted users during session creation * fix: fail closed when session creation fails * fix: reject token issuance for inactive users
256 lines
13 KiB
ERB
256 lines
13 KiB
ERB
<%= content_for :page_title, t(".title") %>
|
|
|
|
<div class="bg-container rounded-xl shadow-border-xs p-4 space-y-6">
|
|
<div>
|
|
<p class="text-sm text-secondary"><%= t(".description") %></p>
|
|
</div>
|
|
|
|
<!-- Filters -->
|
|
<div>
|
|
<%= form_with url: admin_users_path, method: :get, class: "flex gap-4 items-end flex-wrap" do |f| %>
|
|
<div class="w-full md:w-auto">
|
|
<%= f.label :role, t(".filters.role"), class: "block text-sm font-medium text-primary mb-1" %>
|
|
<%= f.select :role,
|
|
options_for_select(
|
|
[[t(".filters.role_all"), ""], [t(".roles.guest"), "guest"], [t(".roles.member"), "member"], [t(".roles.admin"), "admin"], [t(".roles.super_admin"), "super_admin"]],
|
|
params[:role]
|
|
),
|
|
{},
|
|
class: "rounded-lg border border-primary px-3 py-2 text-sm bg-container-inset text-primary w-full" %>
|
|
</div>
|
|
<div class="w-full md:w-auto">
|
|
<%= f.label :trial_status, t(".filters.trial_status"), class: "block text-sm font-medium text-primary mb-1" %>
|
|
<%= f.select :trial_status,
|
|
options_for_select(
|
|
[[t(".filters.trial_all"), ""], [t(".filters.trial_expiring_soon"), "expiring_soon"], [t(".filters.trial_trialing"), "trialing"]],
|
|
params[:trial_status]
|
|
),
|
|
{},
|
|
class: "rounded-lg border border-primary px-3 py-2 text-sm bg-container-inset text-primary w-full" %>
|
|
</div>
|
|
<%= render DS::Button.new(variant: :primary, size: :md, type: "submit", text: t(".filters.submit"), class: "md:w-auto w-full justify-center") %>
|
|
<% end %>
|
|
</div>
|
|
|
|
<!-- Summary: trials expiring in next 7 days -->
|
|
<div class="grid grid-cols-1 md:grid-cols-4 gap-4">
|
|
<div class="bg-container-inset rounded-lg p-4">
|
|
<div class="flex items-center gap-2 mb-2">
|
|
<%= icon "calendar-clock", class: "w-5 h-5 text-secondary" %>
|
|
<p class="text-xs font-medium text-secondary uppercase"><%= t(".summary.trials_expiring_7_days") %></p>
|
|
</div>
|
|
<p class="text-2xl font-semibold text-primary"><%= @trials_expiring_in_7_days %></p>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Families/Groups & Users -->
|
|
<div>
|
|
<h2 class="text-lg font-semibold text-primary mb-3"><%= t(".section_title") %></h2>
|
|
|
|
<% if @families_with_users.any? %>
|
|
<div class="space-y-4">
|
|
<% @families_with_users.each do |family, users| %>
|
|
<% pending_invitations = @invitations_by_family[family.id] || [] %>
|
|
<%= render DS::Disclosure.new(
|
|
variant: :bare,
|
|
summary_class: "list-none focus-ring flex items-center justify-between gap-4 px-4 py-3 cursor-pointer select-none hover:bg-surface-hover",
|
|
class: "bg-container-inset rounded-lg overflow-hidden",
|
|
data: {
|
|
controller: "admin-invitation-delete",
|
|
admin_invitation_delete_delete_all_label_value: t(".invitations.delete_all")
|
|
}
|
|
) do |disclosure| %>
|
|
<% disclosure.with_summary_content do %>
|
|
<div class="flex items-center gap-3">
|
|
<%= icon "users", class: "w-5 h-5 text-secondary shrink-0" %>
|
|
<div>
|
|
<p class="font-semibold text-primary"><%= family.name.presence || t(".unnamed_family") %></p>
|
|
<p class="text-xs text-secondary">
|
|
<%= t(".family_summary",
|
|
members: users.size,
|
|
accounts: number_with_delimiter(@accounts_count_by_family[family.id] || 0),
|
|
transactions: number_with_delimiter(@entries_count_by_family[family.id] || 0)) %>
|
|
</p>
|
|
</div>
|
|
</div>
|
|
<div class="flex items-center gap-4 shrink-0">
|
|
<% sub = family.subscription %>
|
|
<% if sub&.trialing? %>
|
|
<span class="text-xs text-secondary">
|
|
<%= t(".table.trial_ends_at") %>: <%= sub.trial_ends_at&.to_fs(:long) || t(".not_available") %>
|
|
</span>
|
|
<% elsif sub %>
|
|
<%= render DS::Pill.new(label: sub.status.humanize, tone: sub.active? ? :success : :neutral) %>
|
|
<% else %>
|
|
<span class="text-xs text-secondary"><%= t(".no_subscription") %></span>
|
|
<% end %>
|
|
<%= icon "chevron-down", class: "w-4 h-4 text-secondary transition-transform group-open:rotate-180" %>
|
|
</div>
|
|
<% end %>
|
|
|
|
<div class="border-t border-primary">
|
|
<table class="w-full">
|
|
<thead class="bg-surface border-b border-primary">
|
|
<tr>
|
|
<th class="px-4 py-2 text-left text-xs font-medium text-secondary uppercase"><%= t(".table.user") %></th>
|
|
<th class="px-4 py-2 text-left text-xs font-medium text-secondary uppercase"><%= t(".table.last_login") %></th>
|
|
<th class="px-4 py-2 text-right text-xs font-medium text-secondary uppercase"><%= t(".table.session_count") %></th>
|
|
<th class="px-4 py-2 text-right text-xs font-medium text-secondary uppercase"><%= t(".table.role") %></th>
|
|
</tr>
|
|
</thead>
|
|
<tbody class="divide-y divide-alpha-black-200 theme-dark:divide-alpha-white-200">
|
|
<% users.each do |user| %>
|
|
<tr>
|
|
<td class="px-4 py-3">
|
|
<div class="flex items-center gap-3">
|
|
<div class="w-8 h-8 rounded-full bg-surface flex items-center justify-center shrink-0">
|
|
<span class="text-sm font-medium text-primary"><%= user.initials %></span>
|
|
</div>
|
|
<div>
|
|
<p class="font-medium text-primary"><%= user.display_name %></p>
|
|
<p class="text-sm text-secondary"><%= user.email %></p>
|
|
</div>
|
|
</div>
|
|
</td>
|
|
<td class="px-4 py-3 text-sm text-primary whitespace-nowrap">
|
|
<%= @last_login_by_user[user.id]&.to_fs(:long) || t(".table.never") %>
|
|
</td>
|
|
<td class="px-4 py-3 text-sm text-primary text-right whitespace-nowrap">
|
|
<%= number_with_delimiter(@sessions_count_by_user[user.id] || 0) %>
|
|
</td>
|
|
<td class="px-4 py-3 text-right">
|
|
<% if user.id == Current.user.id %>
|
|
<span class="text-sm text-secondary"><%= t(".you") %></span>
|
|
<% else %>
|
|
<div class="flex items-center justify-end gap-2">
|
|
<%= form_with model: [:admin, user], method: :patch, class: "flex items-center", data: { controller: "auto-submit-form" } do |form| %>
|
|
<%= form.select :role,
|
|
options_for_select([
|
|
[t(".roles.guest"), "guest"],
|
|
[t(".roles.member"), "member"],
|
|
[t(".roles.admin"), "admin"],
|
|
[t(".roles.super_admin"), "super_admin"]
|
|
], user.role),
|
|
{},
|
|
class: "text-sm rounded-lg border border-primary bg-container text-primary px-2 py-1",
|
|
data: { auto_submit_form_target: "auto" } %>
|
|
<% end %>
|
|
<% unless user.super_admin? && user.active? && @active_super_admin_count <= 1 %>
|
|
<%= render DS::Button.new(
|
|
text: t(".table.remove"),
|
|
href: deletion_admin_user_path(user),
|
|
method: :get,
|
|
frame: "modal",
|
|
variant: :outline_destructive,
|
|
size: :sm
|
|
) %>
|
|
<% end %>
|
|
</div>
|
|
<% end %>
|
|
</td>
|
|
</tr>
|
|
<% end %>
|
|
</tbody>
|
|
<% if pending_invitations.any? %>
|
|
<tbody class="divide-y divide-alpha-black-200 theme-dark:divide-alpha-white-200 border-t border-dashed border-primary">
|
|
<% pending_invitations.each do |invitation| %>
|
|
<tr class="bg-destructive/5">
|
|
<td class="px-4 py-3">
|
|
<div class="flex items-center gap-3">
|
|
<%= icon "mail", class: "w-5 h-5 text-secondary shrink-0" %>
|
|
<div>
|
|
<p class="font-medium text-secondary italic"><%= invitation.email %></p>
|
|
<p class="text-xs text-secondary"><%= t(".invitations.pending_label") %></p>
|
|
</div>
|
|
</div>
|
|
</td>
|
|
<td class="px-4 py-3 text-sm text-secondary whitespace-nowrap">
|
|
<%= t(".invitations.expires", date: invitation.expires_at.to_fs(:long)) %>
|
|
</td>
|
|
<td class="px-4 py-3 text-sm text-secondary text-right whitespace-nowrap">
|
|
—
|
|
</td>
|
|
<td class="px-4 py-3 text-right">
|
|
<%= form_with url: admin_invitation_path(invitation), method: :delete, class: "inline" do |f| %>
|
|
<%= render DS::Button.new(
|
|
text: t(".invitations.delete"),
|
|
type: "submit",
|
|
variant: :outline_destructive,
|
|
size: :sm,
|
|
data: {
|
|
admin_invitation_delete_target: "button",
|
|
action: "click->admin-invitation-delete#handleClick"
|
|
}
|
|
) %>
|
|
<% end %>
|
|
</td>
|
|
</tr>
|
|
<% end %>
|
|
</tbody>
|
|
<% end %>
|
|
</table>
|
|
<% if pending_invitations.any? %>
|
|
<%= form_with url: invitations_admin_family_path(family), method: :delete,
|
|
data: { admin_invitation_delete_target: "destroyAllForm" },
|
|
class: "hidden" do |f| %>
|
|
<% end %>
|
|
<% end %>
|
|
</div>
|
|
<% end %>
|
|
<% end %>
|
|
</div>
|
|
<% else %>
|
|
<div class="bg-container-inset rounded-lg p-8 text-center">
|
|
<%= icon "users", class: "w-12 h-12 mx-auto text-secondary mb-3" %>
|
|
<p class="text-secondary"><%= t(".no_users") %></p>
|
|
</div>
|
|
<% end %>
|
|
</div>
|
|
|
|
<% if @sso_identity_blocks.any? %>
|
|
<%= settings_section title: t(".removed_sso_identities.title"), collapsible: true, open: false do %>
|
|
<p class="text-sm text-secondary mb-4"><%= t(".removed_sso_identities.description") %></p>
|
|
<div class="space-y-2">
|
|
<% @sso_identity_blocks.each do |block| %>
|
|
<div class="flex items-center justify-between gap-4 rounded-lg border border-primary p-3">
|
|
<div>
|
|
<p class="font-medium text-primary"><%= block.identity_label %></p>
|
|
<p class="text-sm text-secondary"><%= block.provider %> · <%= l(block.created_at, format: :long) %></p>
|
|
</div>
|
|
<%= form_with url: admin_sso_identity_block_path(block), method: :delete do %>
|
|
<%= render DS::Button.new(
|
|
text: t(".removed_sso_identities.allow_again"),
|
|
type: "submit",
|
|
variant: :outline_destructive,
|
|
size: :sm,
|
|
data: { turbo_confirm: t(".removed_sso_identities.confirm", email: block.identity_label) }
|
|
) %>
|
|
<% end %>
|
|
</div>
|
|
<% end %>
|
|
</div>
|
|
<% end %>
|
|
<% end %>
|
|
|
|
<%= settings_section title: t(".role_descriptions_title"), collapsible: true, open: true do %>
|
|
<div class="space-y-3 text-sm">
|
|
<div class="flex items-start gap-3">
|
|
<%= render DS::Pill.new(label: t(".roles.guest"), tone: :neutral) %>
|
|
<p class="text-secondary"><%= t(".role_descriptions.guest") %></p>
|
|
</div>
|
|
<div class="flex items-start gap-3">
|
|
<%= render DS::Pill.new(label: t(".roles.member"), tone: :neutral) %>
|
|
<p class="text-secondary"><%= t(".role_descriptions.member") %></p>
|
|
</div>
|
|
<div class="flex items-start gap-3">
|
|
<%= render DS::Pill.new(label: t(".roles.admin"), tone: :neutral) %>
|
|
<p class="text-secondary"><%= t(".role_descriptions.admin") %></p>
|
|
</div>
|
|
<div class="flex items-start gap-3">
|
|
<%= render DS::Pill.new(label: t(".roles.super_admin"), tone: :success) %>
|
|
<p class="text-secondary"><%= t(".role_descriptions.super_admin") %></p>
|
|
</div>
|
|
</div>
|
|
<% end %>
|
|
</div>
|