You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

387 lines
15 KiB

from django.core.management.base import BaseCommand
from django.db import transaction
from apps.account.models.role import Role, ALL_PERMISSION_FIELDS
DEFAULT_ROLES = [
{
"name": "User",
"slug": "user",
"description": "Standard community member with basic profile, messaging, learning, and participation privileges.",
"is_default": True,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": False,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": False,
"can_moderate_chat": False,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": False,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": False,
"can_publish_courses": False,
"can_issue_certificates": False,
"can_grade_submissions": False,
"has_premium_lms_access": False,
"can_request_meetings": True,
"can_accept_meetings": False,
"can_register_events": True,
"can_create_events": False,
"can_publish_events": False,
"can_checkin_attendees": False,
"can_export_attendee_list": False,
"can_volunteer": True,
"can_create_projects": False,
"can_manage_project_tasks": False,
"can_approve_projects": False,
"can_make_donations": True,
"can_create_donation_campaigns": False,
"can_view_donation_reports": False,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": False,
"can_submit_forms": True,
"can_create_forms": False,
"can_export_form_data": False,
"can_view_diplomatic_reports": False,
"can_create_diplomatic_reports": False,
"can_access_admin_panel": False,
"can_manage_users": False,
"can_ban_users": False,
"can_view_analytics": False,
}
},
{
"name": "Verified User",
"slug": "verified_user",
"description": "Verified community member with authenticated identity, video calling, and direct content publishing.",
"is_default": False,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": False,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": True,
"can_moderate_chat": False,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": True,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": False,
"can_publish_courses": False,
"can_issue_certificates": False,
"can_grade_submissions": False,
"has_premium_lms_access": True,
"can_request_meetings": True,
"can_accept_meetings": False,
"can_register_events": True,
"can_create_events": True,
"can_publish_events": False,
"can_checkin_attendees": False,
"can_export_attendee_list": False,
"can_volunteer": True,
"can_create_projects": False,
"can_manage_project_tasks": False,
"can_approve_projects": False,
"can_make_donations": True,
"can_create_donation_campaigns": False,
"can_view_donation_reports": False,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": False,
"can_submit_forms": True,
"can_create_forms": False,
"can_export_form_data": False,
"can_view_diplomatic_reports": False,
"can_create_diplomatic_reports": False,
"can_access_admin_panel": False,
"can_manage_users": False,
"can_ban_users": False,
"can_view_analytics": False,
}
},
{
"name": "Institution Admin",
"slug": "institution_admin",
"description": "Administrator of an Islamic center, university, or institution with management over courses, events, meetings, and campaigns.",
"is_default": False,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": True,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": True,
"can_moderate_chat": False,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": True,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": True,
"can_publish_courses": True,
"can_issue_certificates": True,
"can_grade_submissions": True,
"has_premium_lms_access": True,
"can_request_meetings": True,
"can_accept_meetings": True,
"can_register_events": True,
"can_create_events": True,
"can_publish_events": True,
"can_checkin_attendees": True,
"can_export_attendee_list": True,
"can_volunteer": True,
"can_create_projects": True,
"can_manage_project_tasks": True,
"can_approve_projects": False,
"can_make_donations": True,
"can_create_donation_campaigns": True,
"can_view_donation_reports": True,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": False,
"can_submit_forms": True,
"can_create_forms": True,
"can_export_form_data": True,
"can_view_diplomatic_reports": True,
"can_create_diplomatic_reports": False,
"can_access_admin_panel": False,
"can_manage_users": False,
"can_ban_users": False,
"can_view_analytics": False,
}
},
{
"name": "Institution Owner",
"slug": "institution_owner",
"description": "Owner / Primary Representative of an institution with full oversight over institutional projects, campaigns, and diplomacy.",
"is_default": False,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": True,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": True,
"can_moderate_chat": False,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": True,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": True,
"can_publish_courses": True,
"can_issue_certificates": True,
"can_grade_submissions": True,
"has_premium_lms_access": True,
"can_request_meetings": True,
"can_accept_meetings": True,
"can_register_events": True,
"can_create_events": True,
"can_publish_events": True,
"can_checkin_attendees": True,
"can_export_attendee_list": True,
"can_volunteer": True,
"can_create_projects": True,
"can_manage_project_tasks": True,
"can_approve_projects": True,
"can_make_donations": True,
"can_create_donation_campaigns": True,
"can_view_donation_reports": True,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": False,
"can_submit_forms": True,
"can_create_forms": True,
"can_export_form_data": True,
"can_view_diplomatic_reports": True,
"can_create_diplomatic_reports": True,
"can_access_admin_panel": False,
"can_manage_users": False,
"can_ban_users": False,
"can_view_analytics": False,
}
},
{
"name": "Content Moderator",
"slug": "content_moderator",
"description": "Community moderator responsible for chat safety, content review, and ticket management.",
"is_default": False,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": False,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": False,
"can_moderate_chat": True,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": True,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": False,
"can_publish_courses": False,
"can_issue_certificates": False,
"can_grade_submissions": False,
"has_premium_lms_access": False,
"can_request_meetings": True,
"can_accept_meetings": False,
"can_register_events": True,
"can_create_events": False,
"can_publish_events": False,
"can_checkin_attendees": False,
"can_export_attendee_list": False,
"can_volunteer": True,
"can_create_projects": False,
"can_manage_project_tasks": False,
"can_approve_projects": False,
"can_make_donations": True,
"can_create_donation_campaigns": False,
"can_view_donation_reports": False,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": True,
"can_submit_forms": True,
"can_create_forms": False,
"can_export_form_data": False,
"can_view_diplomatic_reports": False,
"can_create_diplomatic_reports": False,
"can_access_admin_panel": True,
"can_manage_users": False,
"can_ban_users": False,
"can_view_analytics": False,
}
},
{
"name": "Regional Admin",
"slug": "regional_admin",
"description": "Regional supervisor with authority over regional institutions, user accounts, and community analytics.",
"is_default": False,
"is_system": True,
"permissions": {
"is_searchable": True,
"can_submit_verification": True,
"can_view_full_profiles": True,
"can_manage_institutions": True,
"can_send_direct_messages": True,
"can_create_group_chats": True,
"can_start_video_calls": True,
"can_moderate_chat": True,
"is_chat_muted": False,
"can_create_posts": True,
"can_publish_posts_directly": True,
"can_edit_own_posts": True,
"can_delete_own_posts": True,
"can_comment": True,
"can_enroll_courses": True,
"can_create_courses": True,
"can_publish_courses": True,
"can_issue_certificates": True,
"can_grade_submissions": True,
"has_premium_lms_access": True,
"can_request_meetings": True,
"can_accept_meetings": True,
"can_register_events": True,
"can_create_events": True,
"can_publish_events": True,
"can_checkin_attendees": True,
"can_export_attendee_list": True,
"can_volunteer": True,
"can_create_projects": True,
"can_manage_project_tasks": True,
"can_approve_projects": True,
"can_make_donations": True,
"can_create_donation_campaigns": True,
"can_view_donation_reports": True,
"can_create_tickets": True,
"can_reply_tickets": True,
"can_manage_tickets": True,
"can_submit_forms": True,
"can_create_forms": True,
"can_export_form_data": True,
"can_view_diplomatic_reports": True,
"can_create_diplomatic_reports": True,
"can_access_admin_panel": True,
"can_manage_users": True,
"can_ban_users": True,
"can_view_analytics": True,
}
},
{
"name": "Super Administrator",
"slug": "super_admin",
"description": "Master administrative role with all permissions, total access control, and full platform authority.",
"is_default": False,
"is_system": True,
"permissions": {perm: (perm != "is_chat_muted") for perm in ALL_PERMISSION_FIELDS}
},
]
class Command(BaseCommand):
help = "Seed the 7 default configurable system roles with their exact permission matrix"
@transaction.atomic
def handle(self, *args, **options):
self.stdout.write("Seeding default system roles...")
created_count = 0
updated_count = 0
for role_data in DEFAULT_ROLES:
perms = role_data.pop("permissions")
role, created = Role.objects.get_or_create(
slug=role_data["slug"],
defaults={
"name": role_data["name"],
"description": role_data["description"],
"is_default": role_data["is_default"],
"is_system": role_data["is_system"],
**perms
}
)
if not created:
# Update role configuration if existing
role.name = role_data["name"]
role.description = role_data["description"]
role.is_default = role_data["is_default"]
role.is_system = role_data["is_system"]
for perm, val in perms.items():
setattr(role, perm, val)
role.save()
updated_count += 1
self.stdout.write(self.style.SUCCESS(f" [✓] Updated role: {role.name} ({role.slug})"))
else:
created_count += 1
self.stdout.write(self.style.SUCCESS(f" [+] Created role: {role.name} ({role.slug})"))
self.stdout.write(self.style.SUCCESS(
f"Successfully finished seeding roles: {created_count} created, {updated_count} updated."
))