mirror of
https://github.com/melgarafael/DeskcommCRM.git
synced 2026-10-02 01:28:34 +08:00
GET /api/v1/admin/platform-admins: requirePlatformAdmin, service-role list of platform_admins with auth.users emails resolved (granted_by, revoked_by, target user). POST/PATCH/DELETE return 405 explicitly with message pointing to Spec 01 §3.4 T-04 (DBA-only mutation). UI: - /admin/platform-admins: prominent DBAOnlyNotice (blue alert with T-04 reference + runbook link) + PlatformAdminsTable (user, granted_at relative, granted_by, scope, mfa_required, status active/revoked, reason tooltip) - ZERO mutation buttons by design Closes EPIC-11 — Super-Admin Platform fully wired (14/14 waves). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
36 lines
926 B
TypeScript
36 lines
926 B
TypeScript
"use client";
|
|
import { useQuery } from "@tanstack/react-query";
|
|
import { apiClient } from "@/lib/api/client";
|
|
|
|
export interface PlatformAdminEntry {
|
|
id: string;
|
|
user_id: string;
|
|
user_email: string | null;
|
|
user_name: string | null;
|
|
granted_by: string | null;
|
|
granted_by_email: string | null;
|
|
granted_at: string;
|
|
scope: string | null;
|
|
mfa_required: boolean;
|
|
reason: string | null;
|
|
revoked_at: string | null;
|
|
revoked_by: string | null;
|
|
revoked_by_email: string | null;
|
|
revoke_reason: string | null;
|
|
}
|
|
|
|
interface PlatformAdminsResponse {
|
|
data: PlatformAdminEntry[];
|
|
}
|
|
|
|
export function useAdminPlatformAdmins() {
|
|
return useQuery({
|
|
queryKey: ["admin", "platform-admins"],
|
|
queryFn: () =>
|
|
apiClient
|
|
.get<PlatformAdminsResponse>("/api/v1/admin/platform-admins")
|
|
.then((r) => r.data),
|
|
staleTime: 5 * 60 * 1000, // 5 min — changes are rare (DBA-only mutations)
|
|
});
|
|
}
|