divan/api
Anas Rashid d72c14f8bd Permissions (IAM): L2/L1 moderators and scoped grants (#29)
- Roles: reader, mod-l2, mod-l1, admin. Grants: scope (all, poet, book/section with everything in
  it, one work) x content (poets, books, works, dictionary) x actions (create, edit, delete,
  arrange); dictionary grants are site-wide. can() in api/src/permissions.ts is the one check.
- Admin API and pages: role dropdown on /admin; /admin/user/:id lists a moderator's grants, adds
  them (target by poet id or page link) and revokes them; demoting a moderator clears their grants;
  grant and revoke go to the audit log.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 23:13:06 +02:00
..
src Permissions (IAM): L2/L1 moderators and scoped grants (#29) 2026-10-08 23:13:06 +02:00
.gitignore Divan v2: Node.js API + PostgreSQL (proof of concept) 2026-10-08 20:24:20 +02:00
package-lock.json Divan v2: Node.js API + PostgreSQL (proof of concept) 2026-10-08 20:24:20 +02:00
package.json Admin panel: users, password reset on request, disable, roles, delete, audit log (#27) 2026-10-08 23:08:19 +02:00