Fundament: ISMS-Module entfernt; Craftvia-Rollen, Module, Navigation, i18n-Split

- ISMS-Routen, Actions, Server-/Lib-Code, Komponenten, Prisma-Modelle, Seeds,
  Importer, Skripte und ISMS-Tests entfernt (Fundament bleibt: Auth, Identity,
  MFA/WebAuthn, RBAC, Audit, Mail, Storage, Backup/DSGVO, Plattform-Admin)
- Schema auf Fundament-Modelle reduziert; TenantSettings generisch (+phone/email)
- TENANT_MODELS (db.ts, backup/topology.ts) und PII-Felder ausgedünnt
- RBAC: Rollen tenant-admin/backoffice/team-lead/technician + Craftvia-Permissions
- Modul-Katalog (customers, sites, teams, work_orders, imports, field, reports,
  emergency, documents, notifications, lotse) + Navigation aus src/lib/nav.ts
- Modul-Routen mit requireModule-Layout und Platzhalterseite
- Message-Katalog je Namespace (messages/<locale>/<namespace>.json), fs-Loader
- check-module-guards: Modul-Key aus src/server/actions/<moduleKey>/
- Provisionierung, Admin-Konsole, Einstellungen, Files-Route, Mail entkoppelt
- Seed minimal (demo/demo2, Nutzer je Rolle); Fundament-Tests auf Role/
  NotificationPreference-Fixtures umgestellt

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-14 11:35:44 +02:00
co-authored by Claude Opus 5
parent c8e6f30a27
commit 8491c7f173
443 changed files with 1325 additions and 87773 deletions
+2 -2
View File
@@ -21,7 +21,7 @@ const ok = (cond: boolean, msg: string) => {
const SLUG = "zz-f06-authz-test";
const EMAIL = "f06-user@zz-authz.test";
const PERM = "asset:write"; // existiert im globalen Permissionskatalog
const PERM = "customer:write"; // existiert im globalen Permissionskatalog
/**
* Repliziert die autoritative Prüfung aus moduleGuard (Option C): Membership-Status +
@@ -94,7 +94,7 @@ async function main() {
const a1 = await authorize(user.id, identity.id);
ok(a1 !== null, "(1) aktives Konto wird gefunden");
ok(a1?.perms.has(PERM) === true, `(1) effektive Rechte enthalten ${PERM}`);
ok(a1?.perms.has("risk:accept") === false, "(1) nicht vergebenes Recht fehlt korrekt");
ok(a1?.perms.has("customer:merge") === false, "(1) nicht vergebenes Recht fehlt korrekt");
// (2) Membership deaktiviert → Query liefert null → Guard wirft „Konto ist nicht aktiv".
await prisma.user.update({ where: { id: user.id }, data: { status: "DEACTIVATED" } });