feat: console role management

Signed-off-by: Sebastian Krupinski <krupinski01@gmail.com>
This commit is contained in:
2026-07-24 21:58:16 -04:00
parent bf14b72a03
commit a723051d11
7 changed files with 548 additions and 1 deletions
@@ -8,6 +8,8 @@ use KTXC\Models\Tenant\DomainCollection;
use KTXC\Models\Tenant\TenantConfiguration;
use KTXC\Models\Tenant\TenantObject;
use KTXC\Service\TenantService;
use KTXC\Stores\UserAccountsStore;
use KTXC\Stores\UserRolesStore;
use KTXF\Utile\UUID;
use Psr\Log\LoggerInterface;
use Symfony\Component\Console\Attribute\AsCommand;
@@ -31,6 +33,8 @@ class TenantCreateCommand extends Command
{
public function __construct(
private readonly TenantService $tenantService,
private readonly UserRolesStore $rolesStore,
private readonly UserAccountsStore $userStore,
private readonly LoggerInterface $logger
) {
parent::__construct();
@@ -44,7 +48,9 @@ class TenantCreateCommand extends Command
->addOption('description', 'd', InputOption::VALUE_REQUIRED, 'Tenant description')
->addOption('identifier', null, InputOption::VALUE_REQUIRED, 'Explicit tenant identifier (defaults to a generated UUID)')
->addOption('disabled', null, InputOption::VALUE_NONE, 'Create the tenant in a disabled state')
->setHelp('This command creates a new tenant with one or more domains. The tenant identifier is generated automatically unless --identifier is provided.')
->addOption('admin-identity', null, InputOption::VALUE_REQUIRED, 'Identity for the bootstrap admin user', 'admin')
->addOption('no-admin-user', null, InputOption::VALUE_NONE, 'Do not create a bootstrap admin user (the admin role is still seeded)')
->setHelp('This command creates a new tenant with one or more domains. The tenant identifier is generated automatically unless --identifier is provided. An "admin" role with full permissions is seeded automatically, along with a bootstrap admin user unless --no-admin-user is passed.')
;
}
@@ -106,6 +112,51 @@ class TenantCreateCommand extends Command
['Domains' => implode(', ', $domains)],
);
$role = $this->rolesStore->createRole($identifier, [
'rid' => 'admin',
'label' => 'Administrator',
'description' => 'Full access to all tenant features',
'permissions' => ['*'],
'system' => true,
]);
$this->logger->info('Default admin role seeded via console', [
'tenant' => $identifier,
'rid' => $role['rid'] ?? null,
'command' => $this->getName(),
]);
$io->text("Default role 'admin' seeded with full permissions.");
if (!$input->getOption('no-admin-user')) {
$adminIdentity = $input->getOption('admin-identity');
if ($this->userStore->fetchByIdentity($identifier, $adminIdentity)) {
$io->warning("User '{$adminIdentity}' already exists in tenant '{$identifier}'; skipping admin user creation.");
} else {
$this->userStore->createUser($identifier, [
'identity' => $adminIdentity,
'label' => 'Administrator',
'enabled' => true,
'roles' => ['admin'],
'profile' => [],
'settings' => [],
'provider' => null,
'provider_subject' => null,
'provider_managed_fields' => [],
]);
$this->logger->info('Bootstrap admin user created via console', [
'tenant' => $identifier,
'identity' => $adminIdentity,
'command' => $this->getName(),
]);
$io->text("Admin user '{$adminIdentity}' created with the 'admin' role.");
$io->note("Set a credential for this account using the auth provider module you have installed, e.g.: php bin/console user:password {$identifier} {$adminIdentity}");
}
}
return Command::SUCCESS;
} catch (\Throwable $e) {