feat(seller): multi-user seller dashboard (owner + staff) #2

Merged
ArdaSamadi merged 3 commits from feat/seller-team into main 2026-07-01 14:04:20 +00:00
Owner

Multi-user seller panel: store Owner (Seller.user) + Staff (SellerMembership, invited by phone). Central seller/permissions.py; authz refactored across product/order/apgs/comment/storefront; owner-only areas (financial/settings/members) stay owner-scoped. Store-aware chat threads (+ IDOR fix), team-wide order/message notifications, and a buyer-inbox vs store-inbox split. Adversarially reviewed; review findings fixed (private-thread leak, non-UUID 500, owner-route guards, robust my-stores).

⚠️ Deploy the backend and frontend feat/seller-team together — they are coupled. Run migrations (seller 0005, chat 0002) after deploy.

🤖 Generated with Claude Code

Multi-user seller panel: store Owner (Seller.user) + Staff (SellerMembership, invited by phone). Central seller/permissions.py; authz refactored across product/order/apgs/comment/storefront; owner-only areas (financial/settings/members) stay owner-scoped. Store-aware chat threads (+ IDOR fix), team-wide order/message notifications, and a buyer-inbox vs store-inbox split. Adversarially reviewed; review findings fixed (private-thread leak, non-UUID 500, owner-route guards, robust my-stores). ⚠️ Deploy the backend and frontend feat/seller-team together — they are coupled. Run migrations (seller 0005, chat 0002) after deploy. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
ArdaSamadi added 3 commits 2026-07-01 14:04:18 +00:00
Seller dashboard threads (type="store") now fetch the store's inbox via
useGetStoreThreads(storeId) -> /threads/list/?store_id=; the profile threads page
(type="user") keeps the personal buyer inbox. Depends on the seller-team backend
(store-aware threads + store_id-by-username), so it ships on this branch, not main.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- useMyStores + team hooks (invite by phone / list / remove) in use-seller-hooks.
- useStoreOwnership rewritten to allow staff (not just the owner) via my-stores;
  exposes `role` so callers can gate owner-only UI, and no longer redirects
  members away from a store they help manage.
- Store settings: owner-only items (financial, shipping, edit store, instagram
  sync, team) hidden from staff; new "مدیریت اعضای تیم" entry (owner-only).
- New /store/:storeId/team page: invite by phone + members list with pending/
  active status + remove (owner-only, redirects staff). MyLayout keeps store mode
  on the team route.
- StoreForm edit is owner-only (redirects staff). Profile "enter my store" now
  routes owners to their store and staff to the store they manage.
- Chat already split earlier: seller inbox vs personal buyer inbox.

Depends on the seller-team backend; ships on this branch, not main.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Review fixes:
- useMyStores throws on a failed response instead of resolving to [] — a
  transient 401/blip no longer looks like "no stores" and bounces an owner off
  their own dashboard (query stays in error/retry, keeps prior data).
- Add useRequireOwner() guard and apply it to the owner-only routes
  (financial-dashboard + its cash-funds/reports/transactions sub-routes and
  shipping-method) so staff who hit those URLs directly are redirected to the
  dashboard. (Financial data was already backend-protected; this is the matching
  client-side gate.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ArdaSamadi merged commit ba8e839959 into main 2026-07-01 14:04:20 +00:00
ArdaSamadi deleted branch feat/seller-team 2026-07-01 14:04:20 +00:00
Sign in to join this conversation.
No reviewers
No Label
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: Sotoontech/Vitron-Front#2
No description provided.