移除用户系统级角色,权限完全迁移至项目级管理

- 用户注册/创建不再需要选择角色,账号管理只管资料和状态
- 移除前后端所有系统级 role 字段的暴露,改用 is_admin 标识管理员
- PM(项目负责人)角色自动拥有全部项目权限且不可修改
- 系统管理员在项目中的成员身份不可被删除
- 管理界面全面美化

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Cheng Zhou
2026-05-20 15:52:17 +08:00
parent 6cefa620e4
commit 5b97ea32ab
35 changed files with 1937 additions and 481 deletions
+4 -3
View File
@@ -1,10 +1,11 @@
import { describe, expect, it } from "vitest";
import { getProjectRole, getSystemRole, isSystemAdmin } from "./roles";
import { getProjectRole, isSystemAdmin } from "./roles";
describe("role helpers", () => {
it("keeps system admin separate from project admin", () => {
expect(isSystemAdmin({ role: "ADMIN" } as any)).toBe(true);
expect(getSystemRole({ role: "ADMIN" } as any)).toBe("ADMIN");
expect(isSystemAdmin({ is_admin: true } as any)).toBe(true);
expect(isSystemAdmin({ is_admin: false } as any)).toBe(false);
expect(isSystemAdmin(null)).toBe(false);
expect(getProjectRole({ role_in_study: null } as any, null)).toBeNull();
});
+1 -3
View File
@@ -1,8 +1,6 @@
import type { Study, UserInfo } from "../types/api";
export const getSystemRole = (user?: Pick<UserInfo, "role"> | null) => user?.role || null;
export const isSystemAdmin = (user?: Pick<UserInfo, "role"> | null) => getSystemRole(user) === "ADMIN";
export const isSystemAdmin = (user?: Pick<UserInfo, "is_admin"> | null) => !!user?.is_admin;
export const getProjectRole = (study?: Pick<Study, "role_in_study"> | null, currentStudyRole?: string | null) =>
currentStudyRole || study?.role_in_study || null;