The seeded account is the single admin; it can create author accounts on the new /admin/users page (username + password) and grant each one access to specific tags. Authors sign in to a Posts-only panel where they can write, edit, publish, and unpublish their own posts — every post must carry at least one granted tag, tags outside the grants are rejected server-side, and only the admin can create tags or delete posts (or anything else: pages, comments, settings, and backups stay admin-only). Admin-only URLs bounce authors to their post list, and foreign post editors 404. posts.author_id records ownership; deleting an account keeps its posts as unowned, admin-managed rows and signs the account out everywhere. Backups (export v3) store the owner's username per post and re-attach ownership on import when the account still exists. Also fixes a latent form bug: a missing newTags field (author forms don't render it) failed zod validation with an invisible error. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
20 lines
612 B
TypeScript
20 lines
612 B
TypeScript
import type { Metadata } from "next";
|
|
import { createUserAction } from "@/actions/users";
|
|
import { UserForm } from "@/components/admin/UserForm";
|
|
import { requireAdmin } from "@/lib/auth/dal";
|
|
import { listAllTags } from "@/lib/services/tags";
|
|
|
|
export const metadata: Metadata = { title: "New account" };
|
|
|
|
export default async function NewUserPage() {
|
|
await requireAdmin();
|
|
const allTags = await listAllTags();
|
|
|
|
return (
|
|
<div>
|
|
<h1 className="mb-6 text-2xl font-bold tracking-tight text-ink-bright">New account</h1>
|
|
<UserForm allTags={allTags} action={createUserAction} />
|
|
</div>
|
|
);
|
|
}
|