from django.core.management.base import BaseCommand from django.db import transaction from apps.account.models.role import Role, ALL_PERMISSION_FIELDS DEFAULT_ROLES = [ { "name": "User", "slug": "user", "description": "Standard community member with basic profile, messaging, learning, and participation privileges.", "is_default": True, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": False, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": False, "can_moderate_chat": False, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": False, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": False, "can_publish_courses": False, "can_issue_certificates": False, "can_grade_submissions": False, "has_premium_lms_access": False, "can_request_meetings": True, "can_accept_meetings": False, "can_register_events": True, "can_create_events": False, "can_publish_events": False, "can_checkin_attendees": False, "can_export_attendee_list": False, "can_volunteer": True, "can_create_projects": False, "can_manage_project_tasks": False, "can_approve_projects": False, "can_make_donations": True, "can_create_donation_campaigns": False, "can_view_donation_reports": False, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": False, "can_submit_forms": True, "can_create_forms": False, "can_export_form_data": False, "can_view_diplomatic_reports": False, "can_create_diplomatic_reports": False, "can_access_admin_panel": False, "can_manage_users": False, "can_ban_users": False, "can_view_analytics": False, } }, { "name": "Verified User", "slug": "verified_user", "description": "Verified community member with authenticated identity, video calling, and direct content publishing.", "is_default": False, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": False, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": True, "can_moderate_chat": False, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": True, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": False, "can_publish_courses": False, "can_issue_certificates": False, "can_grade_submissions": False, "has_premium_lms_access": True, "can_request_meetings": True, "can_accept_meetings": False, "can_register_events": True, "can_create_events": True, "can_publish_events": False, "can_checkin_attendees": False, "can_export_attendee_list": False, "can_volunteer": True, "can_create_projects": False, "can_manage_project_tasks": False, "can_approve_projects": False, "can_make_donations": True, "can_create_donation_campaigns": False, "can_view_donation_reports": False, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": False, "can_submit_forms": True, "can_create_forms": False, "can_export_form_data": False, "can_view_diplomatic_reports": False, "can_create_diplomatic_reports": False, "can_access_admin_panel": False, "can_manage_users": False, "can_ban_users": False, "can_view_analytics": False, } }, { "name": "Institution Admin", "slug": "institution_admin", "description": "Administrator of an Islamic center, university, or institution with management over courses, events, meetings, and campaigns.", "is_default": False, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": True, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": True, "can_moderate_chat": False, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": True, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": True, "can_publish_courses": True, "can_issue_certificates": True, "can_grade_submissions": True, "has_premium_lms_access": True, "can_request_meetings": True, "can_accept_meetings": True, "can_register_events": True, "can_create_events": True, "can_publish_events": True, "can_checkin_attendees": True, "can_export_attendee_list": True, "can_volunteer": True, "can_create_projects": True, "can_manage_project_tasks": True, "can_approve_projects": False, "can_make_donations": True, "can_create_donation_campaigns": True, "can_view_donation_reports": True, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": False, "can_submit_forms": True, "can_create_forms": True, "can_export_form_data": True, "can_view_diplomatic_reports": True, "can_create_diplomatic_reports": False, "can_access_admin_panel": False, "can_manage_users": False, "can_ban_users": False, "can_view_analytics": False, } }, { "name": "Institution Owner", "slug": "institution_owner", "description": "Owner / Primary Representative of an institution with full oversight over institutional projects, campaigns, and diplomacy.", "is_default": False, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": True, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": True, "can_moderate_chat": False, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": True, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": True, "can_publish_courses": True, "can_issue_certificates": True, "can_grade_submissions": True, "has_premium_lms_access": True, "can_request_meetings": True, "can_accept_meetings": True, "can_register_events": True, "can_create_events": True, "can_publish_events": True, "can_checkin_attendees": True, "can_export_attendee_list": True, "can_volunteer": True, "can_create_projects": True, "can_manage_project_tasks": True, "can_approve_projects": True, "can_make_donations": True, "can_create_donation_campaigns": True, "can_view_donation_reports": True, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": False, "can_submit_forms": True, "can_create_forms": True, "can_export_form_data": True, "can_view_diplomatic_reports": True, "can_create_diplomatic_reports": True, "can_access_admin_panel": False, "can_manage_users": False, "can_ban_users": False, "can_view_analytics": False, } }, { "name": "Content Moderator", "slug": "content_moderator", "description": "Community moderator responsible for chat safety, content review, and ticket management.", "is_default": False, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": False, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": False, "can_moderate_chat": True, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": True, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": False, "can_publish_courses": False, "can_issue_certificates": False, "can_grade_submissions": False, "has_premium_lms_access": False, "can_request_meetings": True, "can_accept_meetings": False, "can_register_events": True, "can_create_events": False, "can_publish_events": False, "can_checkin_attendees": False, "can_export_attendee_list": False, "can_volunteer": True, "can_create_projects": False, "can_manage_project_tasks": False, "can_approve_projects": False, "can_make_donations": True, "can_create_donation_campaigns": False, "can_view_donation_reports": False, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": True, "can_submit_forms": True, "can_create_forms": False, "can_export_form_data": False, "can_view_diplomatic_reports": False, "can_create_diplomatic_reports": False, "can_access_admin_panel": True, "can_manage_users": False, "can_ban_users": False, "can_view_analytics": False, } }, { "name": "Regional Admin", "slug": "regional_admin", "description": "Regional supervisor with authority over regional institutions, user accounts, and community analytics.", "is_default": False, "is_system": True, "permissions": { "is_searchable": True, "can_submit_verification": True, "can_view_full_profiles": True, "can_manage_institutions": True, "can_send_direct_messages": True, "can_create_group_chats": True, "can_start_video_calls": True, "can_moderate_chat": True, "is_chat_muted": False, "can_create_posts": True, "can_publish_posts_directly": True, "can_edit_own_posts": True, "can_delete_own_posts": True, "can_comment": True, "can_enroll_courses": True, "can_create_courses": True, "can_publish_courses": True, "can_issue_certificates": True, "can_grade_submissions": True, "has_premium_lms_access": True, "can_request_meetings": True, "can_accept_meetings": True, "can_register_events": True, "can_create_events": True, "can_publish_events": True, "can_checkin_attendees": True, "can_export_attendee_list": True, "can_volunteer": True, "can_create_projects": True, "can_manage_project_tasks": True, "can_approve_projects": True, "can_make_donations": True, "can_create_donation_campaigns": True, "can_view_donation_reports": True, "can_create_tickets": True, "can_reply_tickets": True, "can_manage_tickets": True, "can_submit_forms": True, "can_create_forms": True, "can_export_form_data": True, "can_view_diplomatic_reports": True, "can_create_diplomatic_reports": True, "can_access_admin_panel": True, "can_manage_users": True, "can_ban_users": True, "can_view_analytics": True, } }, { "name": "Super Administrator", "slug": "super_admin", "description": "Master administrative role with all permissions, total access control, and full platform authority.", "is_default": False, "is_system": True, "permissions": {perm: (perm != "is_chat_muted") for perm in ALL_PERMISSION_FIELDS} }, ] class Command(BaseCommand): help = "Seed the 7 default configurable system roles with their exact permission matrix" @transaction.atomic def handle(self, *args, **options): self.stdout.write("Seeding default system roles...") created_count = 0 updated_count = 0 for role_data in DEFAULT_ROLES: perms = role_data.pop("permissions") role, created = Role.objects.get_or_create( slug=role_data["slug"], defaults={ "name": role_data["name"], "description": role_data["description"], "is_default": role_data["is_default"], "is_system": role_data["is_system"], **perms } ) if not created: # Update role configuration if existing role.name = role_data["name"] role.description = role_data["description"] role.is_default = role_data["is_default"] role.is_system = role_data["is_system"] for perm, val in perms.items(): setattr(role, perm, val) role.save() updated_count += 1 self.stdout.write(self.style.SUCCESS(f" [✓] Updated role: {role.name} ({role.slug})")) else: created_count += 1 self.stdout.write(self.style.SUCCESS(f" [+] Created role: {role.name} ({role.slug})")) self.stdout.write(self.style.SUCCESS( f"Successfully finished seeding roles: {created_count} created, {updated_count} updated." ))