Add practitioners admin and staff-scoped Care UX.
Deploy Ladill Care / deploy (push) Successful in 43s
Deploy Ladill Care / deploy (push) Successful in 43s
Hospital admins can manage assignable doctors and invite team members from Ladill mailboxes; invited staff only see Care tools they need. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -284,7 +284,10 @@ class SsoLoginController extends Controller
|
||||
private function resolveLanding(IdentityTeamClient $identity, User $user, string $intended): string
|
||||
{
|
||||
try {
|
||||
return $identity->postAuthRedirect($user->ownerRef(), $intended);
|
||||
$access = $identity->appAccess($user->ownerRef(), $intended);
|
||||
\App\Support\StaffUx::remember($access);
|
||||
|
||||
return $access['url'] !== '' ? $access['url'] : $intended;
|
||||
} catch (\Throwable) {
|
||||
return $intended;
|
||||
}
|
||||
|
||||
@@ -6,10 +6,12 @@ use App\Http\Controllers\Controller;
|
||||
use App\Http\Controllers\Care\Concerns\ScopesToAccount;
|
||||
use App\Models\Branch;
|
||||
use App\Models\Member;
|
||||
use App\Models\Practitioner;
|
||||
use App\Services\Care\AuditLogger;
|
||||
use App\Services\Identity\IdentityTeamClient;
|
||||
use Illuminate\Http\RedirectResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Str;
|
||||
use Illuminate\View\View;
|
||||
|
||||
class MemberController extends Controller
|
||||
@@ -43,21 +45,30 @@ class MemberController extends Controller
|
||||
]);
|
||||
}
|
||||
|
||||
public function create(Request $request): View
|
||||
public function create(Request $request, IdentityTeamClient $identity): View
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.members.manage');
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
$branches = Branch::owned($this->ownerRef($request))
|
||||
$branches = Branch::owned($owner)
|
||||
->where('organization_id', $organization->id)
|
||||
->where('is_active', true)
|
||||
->orderBy('name')
|
||||
->get();
|
||||
|
||||
$mailboxOptions = [];
|
||||
try {
|
||||
$mailboxOptions = $identity->mailboxOptions($owner);
|
||||
} catch (\Throwable) {
|
||||
// Identity optional for form rendering.
|
||||
}
|
||||
|
||||
return view('care.admin.members.create', [
|
||||
'organization' => $organization,
|
||||
'branches' => $branches,
|
||||
'roles' => config('care.roles'),
|
||||
'mailboxOptions' => $mailboxOptions,
|
||||
]);
|
||||
}
|
||||
|
||||
@@ -71,6 +82,9 @@ class MemberController extends Controller
|
||||
'email' => ['required', 'email', 'max:255'],
|
||||
'role' => ['required', 'string', 'in:'.implode(',', array_keys(config('care.roles')))],
|
||||
'branch_id' => ['nullable', 'integer', 'exists:care_branches,id'],
|
||||
'create_practitioner' => ['sometimes', 'boolean'],
|
||||
'practitioner_name' => ['nullable', 'string', 'max:255'],
|
||||
'specialty' => ['nullable', 'string', 'max:255'],
|
||||
]);
|
||||
|
||||
$email = strtolower(trim($validated['email']));
|
||||
@@ -106,6 +120,25 @@ class MemberController extends Controller
|
||||
|
||||
AuditLogger::record($owner, 'member.invited', $organization->id, $owner, Member::class, $member->id);
|
||||
|
||||
$createPractitioner = $request->boolean('create_practitioner', $validated['role'] === 'doctor');
|
||||
if ($createPractitioner) {
|
||||
$name = trim((string) ($validated['practitioner_name'] ?? '')) ?: Str::headline(Str::before($email, '@'));
|
||||
Practitioner::query()->firstOrCreate(
|
||||
[
|
||||
'organization_id' => $organization->id,
|
||||
'member_id' => $member->id,
|
||||
],
|
||||
[
|
||||
'owner_ref' => $owner,
|
||||
'branch_id' => $validated['branch_id'] ?? null,
|
||||
'user_ref' => $email,
|
||||
'name' => $name,
|
||||
'specialty' => $validated['specialty'] ?? null,
|
||||
'is_active' => true,
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
return redirect()->route('care.members.index')->with('success', 'Invitation sent to '.$email.'.');
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,195 @@
|
||||
<?php
|
||||
|
||||
namespace App\Http\Controllers\Care;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Http\Controllers\Care\Concerns\ScopesToAccount;
|
||||
use App\Models\Branch;
|
||||
use App\Models\Department;
|
||||
use App\Models\Member;
|
||||
use App\Models\Practitioner;
|
||||
use App\Services\Care\AuditLogger;
|
||||
use Illuminate\Http\RedirectResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\View\View;
|
||||
|
||||
class PractitionerController extends Controller
|
||||
{
|
||||
use ScopesToAccount;
|
||||
|
||||
public function index(Request $request): View
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.view');
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
$practitioners = Practitioner::owned($owner)
|
||||
->where('organization_id', $organization->id)
|
||||
->with(['branch', 'department', 'member'])
|
||||
->orderBy('name')
|
||||
->get();
|
||||
|
||||
return view('care.admin.practitioners.index', [
|
||||
'practitioners' => $practitioners,
|
||||
'organization' => $organization,
|
||||
'heroStats' => [
|
||||
'total' => $practitioners->count(),
|
||||
'active' => $practitioners->where('is_active', true)->count(),
|
||||
'linked' => $practitioners->whereNotNull('member_id')->count(),
|
||||
],
|
||||
]);
|
||||
}
|
||||
|
||||
public function create(Request $request): View
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.manage');
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
return view('care.admin.practitioners.create', [
|
||||
'organization' => $organization,
|
||||
'branches' => $this->activeBranches($owner, $organization->id),
|
||||
'departments' => $this->activeDepartments($owner, $organization->id),
|
||||
'members' => $this->linkableMembers($owner, $organization->id),
|
||||
]);
|
||||
}
|
||||
|
||||
public function store(Request $request): RedirectResponse
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.manage');
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
$validated = $this->validated($request, $owner, $organization->id);
|
||||
|
||||
$member = ! empty($validated['member_id'])
|
||||
? Member::owned($owner)->where('organization_id', $organization->id)->findOrFail($validated['member_id'])
|
||||
: null;
|
||||
|
||||
$practitioner = Practitioner::create([
|
||||
'owner_ref' => $owner,
|
||||
'organization_id' => $organization->id,
|
||||
'branch_id' => $validated['branch_id'] ?? null,
|
||||
'department_id' => $validated['department_id'] ?? null,
|
||||
'member_id' => $member?->id,
|
||||
'user_ref' => $member?->user_ref,
|
||||
'name' => $validated['name'],
|
||||
'specialty' => $validated['specialty'] ?? null,
|
||||
'is_active' => true,
|
||||
]);
|
||||
|
||||
AuditLogger::record($owner, 'practitioner.created', $organization->id, $owner, Practitioner::class, $practitioner->id);
|
||||
|
||||
return redirect()->route('care.practitioners.index')->with('success', 'Practitioner added.');
|
||||
}
|
||||
|
||||
public function edit(Request $request, Practitioner $practitioner): View
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.manage');
|
||||
$this->authorizeOwner($request, $practitioner);
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
return view('care.admin.practitioners.edit', [
|
||||
'practitioner' => $practitioner,
|
||||
'branches' => $this->activeBranches($owner, $organization->id),
|
||||
'departments' => $this->activeDepartments($owner, $organization->id),
|
||||
'members' => $this->linkableMembers($owner, $organization->id),
|
||||
]);
|
||||
}
|
||||
|
||||
public function update(Request $request, Practitioner $practitioner): RedirectResponse
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.manage');
|
||||
$this->authorizeOwner($request, $practitioner);
|
||||
$organization = $this->organization($request);
|
||||
$owner = $this->ownerRef($request);
|
||||
|
||||
$validated = $this->validated($request, $owner, $organization->id);
|
||||
|
||||
$member = ! empty($validated['member_id'])
|
||||
? Member::owned($owner)->where('organization_id', $organization->id)->findOrFail($validated['member_id'])
|
||||
: null;
|
||||
|
||||
$practitioner->update([
|
||||
'branch_id' => $validated['branch_id'] ?? null,
|
||||
'department_id' => $validated['department_id'] ?? null,
|
||||
'member_id' => $member?->id,
|
||||
'user_ref' => $member?->user_ref,
|
||||
'name' => $validated['name'],
|
||||
'specialty' => $validated['specialty'] ?? null,
|
||||
'is_active' => $request->boolean('is_active', true),
|
||||
]);
|
||||
|
||||
AuditLogger::record($owner, 'practitioner.updated', $organization->id, $owner, Practitioner::class, $practitioner->id);
|
||||
|
||||
return redirect()->route('care.practitioners.index')->with('success', 'Practitioner updated.');
|
||||
}
|
||||
|
||||
public function destroy(Request $request, Practitioner $practitioner): RedirectResponse
|
||||
{
|
||||
$this->authorizeAbility($request, 'admin.practitioners.manage');
|
||||
$this->authorizeOwner($request, $practitioner);
|
||||
|
||||
$id = $practitioner->id;
|
||||
$organizationId = $practitioner->organization_id;
|
||||
$practitioner->delete();
|
||||
|
||||
AuditLogger::record($this->ownerRef($request), 'practitioner.deleted', $organizationId, $this->ownerRef($request), Practitioner::class, $id);
|
||||
|
||||
return redirect()->route('care.practitioners.index')->with('success', 'Practitioner removed.');
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{name: string, specialty?: string|null, branch_id?: int|null, department_id?: int|null, member_id?: int|null}
|
||||
*/
|
||||
protected function validated(Request $request, string $owner, int $organizationId): array
|
||||
{
|
||||
$validated = $request->validate([
|
||||
'name' => ['required', 'string', 'max:255'],
|
||||
'specialty' => ['nullable', 'string', 'max:255'],
|
||||
'branch_id' => ['nullable', 'integer', 'exists:care_branches,id'],
|
||||
'department_id' => ['nullable', 'integer', 'exists:care_departments,id'],
|
||||
'member_id' => ['nullable', 'integer', 'exists:care_members,id'],
|
||||
]);
|
||||
|
||||
if (! empty($validated['branch_id'])) {
|
||||
$branch = Branch::owned($owner)->findOrFail($validated['branch_id']);
|
||||
abort_unless($branch->organization_id === $organizationId, 404);
|
||||
}
|
||||
|
||||
if (! empty($validated['department_id'])) {
|
||||
$department = Department::owned($owner)->with('branch')->findOrFail($validated['department_id']);
|
||||
abort_unless($department->branch?->organization_id === $organizationId, 404);
|
||||
}
|
||||
|
||||
return $validated;
|
||||
}
|
||||
|
||||
protected function activeBranches(string $owner, int $organizationId)
|
||||
{
|
||||
return Branch::owned($owner)
|
||||
->where('organization_id', $organizationId)
|
||||
->where('is_active', true)
|
||||
->orderBy('name')
|
||||
->get();
|
||||
}
|
||||
|
||||
protected function activeDepartments(string $owner, int $organizationId)
|
||||
{
|
||||
return Department::owned($owner)
|
||||
->whereHas('branch', fn ($q) => $q->where('organization_id', $organizationId))
|
||||
->where('is_active', true)
|
||||
->orderBy('name')
|
||||
->get();
|
||||
}
|
||||
|
||||
protected function linkableMembers(string $owner, int $organizationId)
|
||||
{
|
||||
return Member::owned($owner)
|
||||
->where('organization_id', $organizationId)
|
||||
->whereIn('role', ['doctor', 'nurse', 'lab_technician', 'pharmacist', 'hospital_admin', 'super_admin'])
|
||||
->orderBy('user_ref')
|
||||
->get();
|
||||
}
|
||||
}
|
||||
@@ -52,5 +52,20 @@ class AppServiceProvider extends ServiceProvider
|
||||
View::composer(['partials.topbar'], function ($view) {
|
||||
$view->with(\App\Support\MobileTopbar::resolve());
|
||||
});
|
||||
|
||||
View::composer(['partials.launcher', 'partials.topbar-desktop-widgets', 'components.app-layout'], function () {
|
||||
$user = auth()->user();
|
||||
if (! $user || session()->has(\App\Support\StaffUx::SESSION_KEY)) {
|
||||
return;
|
||||
}
|
||||
|
||||
try {
|
||||
$access = app(\App\Services\Identity\IdentityTeamClient::class)
|
||||
->appAccess($user->ownerRef());
|
||||
\App\Support\StaffUx::remember($access);
|
||||
} catch (\Throwable) {
|
||||
// Leave fail-open defaults until Identity is available.
|
||||
}
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -45,6 +45,7 @@ class CarePermissions
|
||||
protected array $adminAbilities = [
|
||||
'admin.branches.view', 'admin.branches.manage',
|
||||
'admin.departments.view', 'admin.departments.manage',
|
||||
'admin.practitioners.view', 'admin.practitioners.manage',
|
||||
'admin.members.view', 'admin.members.manage',
|
||||
'settings.view', 'settings.manage',
|
||||
'audit.view', 'audit.export',
|
||||
|
||||
@@ -32,14 +32,40 @@ class IdentityTeamClient
|
||||
return (array) $response->json('data', []);
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{url: string, apps: list<string>, full_access: bool, show_hub: bool, show_billing: bool}
|
||||
*/
|
||||
public function appAccess(string $userPublicId, string $intendedUrl = ''): array
|
||||
{
|
||||
$response = $this->request('get', '/identity/team/post-auth-redirect', array_filter([
|
||||
'user' => $userPublicId,
|
||||
'redirect' => $intendedUrl !== '' ? $intendedUrl : null,
|
||||
]));
|
||||
|
||||
$data = (array) $response->json('data', []);
|
||||
|
||||
return [
|
||||
'url' => (string) ($data['url'] ?? $intendedUrl),
|
||||
'apps' => array_values(array_map('strval', (array) ($data['apps'] ?? []))),
|
||||
'full_access' => (bool) ($data['full_access'] ?? false),
|
||||
'show_hub' => (bool) ($data['show_hub'] ?? ($data['full_access'] ?? false)),
|
||||
'show_billing' => (bool) ($data['show_billing'] ?? ($data['full_access'] ?? false)),
|
||||
];
|
||||
}
|
||||
|
||||
public function postAuthRedirect(string $userPublicId, string $intendedUrl): string
|
||||
{
|
||||
$response = $this->request('get', '/identity/team/post-auth-redirect', [
|
||||
'user' => $userPublicId,
|
||||
'redirect' => $intendedUrl,
|
||||
return $this->appAccess($userPublicId, $intendedUrl)['url'];
|
||||
}
|
||||
|
||||
/** @return list<string> */
|
||||
public function mailboxOptions(string $ownerPublicId): array
|
||||
{
|
||||
$response = $this->request('get', '/identity/team/mailbox-options', [
|
||||
'owner' => $ownerPublicId,
|
||||
]);
|
||||
|
||||
return (string) $response->json('data.url', $intendedUrl);
|
||||
return array_values(array_map('strval', (array) $response->json('data', [])));
|
||||
}
|
||||
|
||||
/** @return list<array<string, mixed>> */
|
||||
|
||||
@@ -0,0 +1,119 @@
|
||||
<?php
|
||||
|
||||
namespace App\Support;
|
||||
|
||||
use Illuminate\Contracts\Auth\Authenticatable;
|
||||
|
||||
/**
|
||||
* Staff vs account-owner UX: team members are limited to the apps they were
|
||||
* invited to. Single-app staff skip Home/launcher; all scoped staff hide
|
||||
* Billing/Wallet (the account owner pays).
|
||||
*
|
||||
* In Care/Meet/etc., values are cached at SSO via Identity (StaffUx::remember).
|
||||
* In the monolith, TeamAccessService resolves them live when available.
|
||||
*/
|
||||
class StaffUx
|
||||
{
|
||||
public const SESSION_KEY = 'ladill.staff_ux';
|
||||
|
||||
public static function showProductHub(?Authenticatable $user = null): bool
|
||||
{
|
||||
$user ??= auth()->user();
|
||||
if (! $user) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($resolved = self::fromTeamAccess($user)) {
|
||||
return $resolved['show_hub'];
|
||||
}
|
||||
|
||||
$cached = session(self::SESSION_KEY);
|
||||
if (is_array($cached) && array_key_exists('show_hub', $cached)) {
|
||||
return (bool) $cached['show_hub'];
|
||||
}
|
||||
|
||||
// Unknown in a silo before SSO cache — assume owner (fail open for hub).
|
||||
return true;
|
||||
}
|
||||
|
||||
public static function showBilling(?Authenticatable $user = null): bool
|
||||
{
|
||||
$user ??= auth()->user();
|
||||
if (! $user) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($resolved = self::fromTeamAccess($user)) {
|
||||
return $resolved['show_billing'];
|
||||
}
|
||||
|
||||
$cached = session(self::SESSION_KEY);
|
||||
if (is_array($cached) && array_key_exists('show_billing', $cached)) {
|
||||
return (bool) $cached['show_billing'];
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/** @return list<string>|null Null means unrestricted / unknown. */
|
||||
public static function allowedAppSlugs(?Authenticatable $user = null): ?array
|
||||
{
|
||||
$user ??= auth()->user();
|
||||
if (! $user) {
|
||||
return [];
|
||||
}
|
||||
|
||||
if ($resolved = self::fromTeamAccess($user)) {
|
||||
return $resolved['full_access'] ? null : $resolved['apps'];
|
||||
}
|
||||
|
||||
$cached = session(self::SESSION_KEY);
|
||||
if (is_array($cached)) {
|
||||
if (! empty($cached['full_access'])) {
|
||||
return null;
|
||||
}
|
||||
if (array_key_exists('apps', $cached) && is_array($cached['apps'])) {
|
||||
return array_values(array_map('strval', $cached['apps']));
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array{full_access?: bool, apps?: list<string>, show_hub?: bool, show_billing?: bool} $payload
|
||||
*/
|
||||
public static function remember(array $payload): void
|
||||
{
|
||||
session([self::SESSION_KEY => [
|
||||
'full_access' => (bool) ($payload['full_access'] ?? false),
|
||||
'apps' => array_values(array_map('strval', (array) ($payload['apps'] ?? []))),
|
||||
'show_hub' => (bool) ($payload['show_hub'] ?? false),
|
||||
'show_billing' => (bool) ($payload['show_billing'] ?? false),
|
||||
]]);
|
||||
}
|
||||
|
||||
/** @return array{full_access: bool, apps: list<string>, show_hub: bool, show_billing: bool}|null */
|
||||
private static function fromTeamAccess(Authenticatable $user): ?array
|
||||
{
|
||||
$service = 'App\\Services\\Team\\TeamAccessService';
|
||||
$userClass = 'App\\Models\\User';
|
||||
|
||||
if (! class_exists($service) || ! is_a($user, $userClass)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
try {
|
||||
$access = app($service);
|
||||
|
||||
return [
|
||||
'full_access' => $access->hasFullProductAccess($user),
|
||||
'apps' => $access->accessibleAppSlugs($user),
|
||||
'show_hub' => $access->showProductHub($user),
|
||||
'show_billing' => $access->showBilling($user),
|
||||
];
|
||||
} catch (\Throwable) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -21,15 +21,25 @@ class UserProfileMenu
|
||||
return [];
|
||||
}
|
||||
|
||||
$showHub = StaffUx::showProductHub($user);
|
||||
$showBilling = StaffUx::showBilling($user);
|
||||
$items = [];
|
||||
|
||||
foreach ([
|
||||
['label' => 'Home', 'path' => '', 'host' => 'home'],
|
||||
['label' => 'Home', 'path' => '', 'host' => 'home', 'requires_hub' => true],
|
||||
['label' => 'Profile', 'path' => 'profile'],
|
||||
['label' => 'Account Settings', 'path' => 'account-settings'],
|
||||
['label' => 'Dashboard', 'path' => 'dashboard'],
|
||||
['label' => 'Billing', 'path' => 'billing'],
|
||||
['label' => 'Billing', 'path' => 'billing', 'requires_billing' => true],
|
||||
] as $link) {
|
||||
if (! empty($link['requires_hub']) && ! $showHub) {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (! empty($link['requires_billing']) && ! $showBilling) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$href = self::platformUrl($link['host'] ?? 'account', $link['path']);
|
||||
|
||||
if (self::isCurrentMenuLink($link, $href)) {
|
||||
@@ -43,7 +53,7 @@ class UserProfileMenu
|
||||
];
|
||||
}
|
||||
|
||||
if (Route::has((string) config('billing.wallet_balance_route', 'wallet.balance'))) {
|
||||
if ($showBilling && Route::has((string) config('billing.wallet_balance_route', 'wallet.balance'))) {
|
||||
$items[] = ['type' => 'wallet'];
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user