Compare commits

...
5 Commits
Author SHA1 Message Date
bachirandClaude Sonnet 5 994c7c7aad Sync admin UI config: compact Gin layout density, hidden nav logo
These had been changed interactively in the admin UI (Gin layout
density -> small, Navigation logo -> hidden) but the exported config
in config/sync had drifted out of sync with the active config -- this
just catches it up.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 11:10:07 +02:00
bachirandClaude Sonnet 5 1f357e5f1c Hide the phantom empty top bar, keep only the Gin sidebar
Core Navigation's top bar only shows itself when its tools/context/
actions regions are non-empty (`:has(:not(:empty))`). With no blocks
placed in those regions, they still contain whitespace text nodes from
Twig's loop scaffolding, which defeats that check -- the bar rendered
anyway, empty, and pushed page content down to make room for it.

Attached globally via hook_page_attachments() rather than scoped to
/lignes or /dashboard, since the Navigation chrome renders on every
authenticated page, not just our custom routes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 11:09:02 +02:00
bachirandClaude Sonnet 5 e7796754ab Remove unused administrator/content_editor roles
Leftover Standard-recipe scaffolding: "administrator" duplicated root's
is_admin bypass, "content_editor" had generic permissions unrelated to
this site's content model (a "tags" vocabulary that doesn't exist here,
nothing for ligne_comptable). Neither was assigned to any user.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 11:08:50 +02:00
bachirandClaude Sonnet 5 a86875c03c Add admin/editeur/user roles for the associates
root (renamed from the default admin/admin account) keeps full,
unrestricted access outside any role system. These three cover the
actual associates:

- user: read-only, 'access content' only -- can browse /lignes and
  /dashboard, nothing else.
- editeur: 'access content' + create/edit any/delete any
  ligne_comptable content -- can enter and correct accounting lines,
  no site configuration.
- admin: identical permission set to editeur for now (per instruction,
  actual config permissions to be scoped later).

Left the pre-existing "administrator" (is_admin bypass -- too broad)
and "content_editor" (generic Standard-recipe scaffolding, permissions
unrelated to ligne_comptable) roles untouched but unused; worth
pruning later if nothing ends up using them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 11:01:07 +02:00
bachirandClaude Sonnet 5 f8ae2d6a9e Lock the site down to authenticated users only
All the ledger data is confidential (real client names, amounts,
associate balances) -- revoke 'access content' from the anonymous
role so nodes, taxonomy terms, and JSON:API all deny anonymous reads
(verified: JSON:API returns an empty data[] + "omitted" notice instead
of the records, /lignes and /dashboard 403).

Set the site's 403 page to /user/login: anonymous visitors hitting "/"
(the front page is /lignes) land on the login form instead of an
access-denied page; authenticated users still land on /lignes as
before since they still hold 'access content' via the authenticated
role.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 10:57:18 +02:00
22 changed files with 165 additions and 107 deletions
+1 -1
View File
@@ -20,7 +20,7 @@ secondary_toolbar_frontend: true
high_contrast_mode: false
accent_color: ''
focus_color: ''
layout_density: default
layout_density: small
show_description_toggle: false
show_user_theme_settings: false
sticky_action_buttons: false
+1 -1
View File
@@ -1,7 +1,7 @@
_core:
default_config_hash: FeJ38-AShWZUh_NwJprQueefcE06zSnUa3cw1lOdjTY
logo:
provider: default
provider: hide
path: ''
max:
filesize: 1048576
@@ -0,0 +1,14 @@
uuid: 581c4991-a2c0-4767-87ca-2405fb63c3a1
langcode: en
status: true
dependencies:
config:
- user.role.admin
module:
- user
id: user_add_role_action.admin
label: 'Add the Admin role to the selected user(s)'
type: user
plugin: user_add_role_action
configuration:
rid: admin
@@ -1,14 +0,0 @@
uuid: 87547109-3fbc-412f-8785-4d29926994fb
langcode: en
status: true
dependencies:
config:
- user.role.administrator
module:
- user
id: user_add_role_action.administrator
label: 'Add the Administrator role to the selected user(s)'
type: user
plugin: user_add_role_action
configuration:
rid: administrator
@@ -1,14 +0,0 @@
uuid: 8aac7eb3-58a1-4cd4-8e41-5822449c0717
langcode: en
status: true
dependencies:
config:
- user.role.content_editor
module:
- user
id: user_add_role_action.content_editor
label: 'Add the Content editor role to the selected user(s)'
type: user
plugin: user_add_role_action
configuration:
rid: content_editor
@@ -0,0 +1,14 @@
uuid: c2b7ee51-1550-4fc0-b43c-32e11e5cf00b
langcode: en
status: true
dependencies:
config:
- user.role.editeur
module:
- user
id: user_add_role_action.editeur
label: 'Add the Éditeur role to the selected user(s)'
type: user
plugin: user_add_role_action
configuration:
rid: editeur
@@ -0,0 +1,14 @@
uuid: 24f21f8a-6568-46c9-84ee-d7480458882a
langcode: en
status: true
dependencies:
config:
- user.role.user
module:
- user
id: user_add_role_action.user
label: 'Add the Utilisateur (lecture seule) role to the selected user(s)'
type: user
plugin: user_add_role_action
configuration:
rid: user
@@ -0,0 +1,14 @@
uuid: cdf63fcb-1d6a-46f8-baaf-1aad7dea8199
langcode: en
status: true
dependencies:
config:
- user.role.admin
module:
- user
id: user_remove_role_action.admin
label: 'Remove the Admin role from the selected user(s)'
type: user
plugin: user_remove_role_action
configuration:
rid: admin
@@ -1,14 +0,0 @@
uuid: cf27d858-625c-4fd0-a566-e77e97ff6f03
langcode: en
status: true
dependencies:
config:
- user.role.administrator
module:
- user
id: user_remove_role_action.administrator
label: 'Remove the Administrator role from the selected user(s)'
type: user
plugin: user_remove_role_action
configuration:
rid: administrator
@@ -1,14 +0,0 @@
uuid: c03c3800-42b0-4ccf-b440-e97fbf345174
langcode: en
status: true
dependencies:
config:
- user.role.content_editor
module:
- user
id: user_remove_role_action.content_editor
label: 'Remove the Content editor role from the selected user(s)'
type: user
plugin: user_remove_role_action
configuration:
rid: content_editor
@@ -0,0 +1,14 @@
uuid: d14de2f6-99a6-4c9a-8eed-c95f83b56607
langcode: en
status: true
dependencies:
config:
- user.role.editeur
module:
- user
id: user_remove_role_action.editeur
label: 'Remove the Éditeur role from the selected user(s)'
type: user
plugin: user_remove_role_action
configuration:
rid: editeur
@@ -0,0 +1,14 @@
uuid: 7198a84f-b1a1-4eae-adf4-f3a9de6cd79f
langcode: en
status: true
dependencies:
config:
- user.role.user
module:
- user
id: user_remove_role_action.user
label: 'Remove the Utilisateur (lecture seule) role from the selected user(s)'
type: user
plugin: user_remove_role_action
configuration:
rid: user
+1 -1
View File
@@ -6,7 +6,7 @@ name: 'Figures Libres - Compta'
mail: admin@example.com
slogan: ''
page:
403: ''
403: /user/login
404: ''
front: /lignes
admin_compact_mode: false
+18
View File
@@ -0,0 +1,18 @@
uuid: 45d15bb6-7222-481f-8306-58f0d207fa97
langcode: en
status: true
dependencies:
config:
- node.type.ligne_comptable
module:
- node
- system
id: admin
label: Admin
weight: 6
is_admin: false
permissions:
- 'access content'
- 'create ligne_comptable content'
- 'delete any ligne_comptable content'
- 'edit any ligne_comptable content'
-11
View File
@@ -1,11 +0,0 @@
uuid: 6af2113b-ad25-4982-bc8f-360b9af97998
langcode: en
status: true
dependencies: { }
_core:
default_config_hash: OeKGIkmZA_c-t6QLH81WNQx8gDCc1MRmxaTuQgxBByU
id: administrator
label: Administrator
weight: 3
is_admin: true
permissions: { }
-2
View File
@@ -6,7 +6,6 @@ dependencies:
- filter.format.restricted_html
module:
- filter
- system
_core:
default_config_hash: Tus1ZTNXKIOnrennR1hnTbc7wUPBXHTUm5UdCpEhJSk
id: anonymous
@@ -14,5 +13,4 @@ label: 'Anonymous user'
weight: 0
is_admin: false
permissions:
- 'access content'
- 'use text format restricted_html'
-35
View File
@@ -1,35 +0,0 @@
uuid: 6e5d280b-fa39-470d-a3db-7ac6d47d5c2a
langcode: en
status: true
dependencies:
config:
- taxonomy.vocabulary.tags
module:
- contextual
- file
- navigation
- node
- path
- system
- taxonomy
_core:
default_config_hash: og55Zu0F-q-X8zG0Ohrls49zws6IrmmosZS-30Es8vw
id: content_editor
label: 'Content editor'
weight: 2
is_admin: false
permissions:
- 'access administration pages'
- 'access content overview'
- 'access contextual links'
- 'access files overview'
- 'access navigation'
- 'administer url aliases'
- 'create terms in tags'
- 'create url aliases'
- 'delete own files'
- 'edit terms in tags'
- 'revert all revisions'
- 'view all revisions'
- 'view own unpublished content'
- 'view the administration theme'
+18
View File
@@ -0,0 +1,18 @@
uuid: ab5bea78-990d-4ca0-af28-d209c60a248e
langcode: en
status: true
dependencies:
config:
- node.type.ligne_comptable
module:
- node
- system
id: editeur
label: Éditeur
weight: 5
is_admin: false
permissions:
- 'access content'
- 'create ligne_comptable content'
- 'delete any ligne_comptable content'
- 'edit any ligne_comptable content'
+12
View File
@@ -0,0 +1,12 @@
uuid: 24f4e46d-c714-486d-b000-f092eb727470
langcode: en
status: true
dependencies:
module:
- system
id: user
label: 'Utilisateur (lecture seule)'
weight: 4
is_admin: false
permissions:
- 'access content'
@@ -0,0 +1,14 @@
/* Core Navigation's top bar (`.top-bar`) only shows itself when its
tools/context/actions regions are non-empty -- but with no blocks placed
there, the regions still contain whitespace text nodes from the Twig
loop scaffolding, which defeats the `:not(:empty)` check. Result: an
empty top bar renders anyway, with the page content pushed down to make
room for it. We only use the Gin sidebar (the left icon rail), so force
the phantom bar off and collapse the space it would otherwise reserve. */
.top-bar {
display: none !important;
}
.top-bar ~ .dialog-off-canvas-main-canvas {
margin-block-start: 0 !important;
}
@@ -24,3 +24,8 @@ dashboard:
dependencies:
- core/drupal
- figli_compta_ledger/vue
admin_chrome:
css:
theme:
css/admin-chrome.css: {}
@@ -152,6 +152,17 @@ function figli_compta_ledger_theme($existing, $type, $theme, $path) {
];
}
/**
* Implements hook_page_attachments().
*
* Core Navigation's top bar renders empty (whitespace-only regions defeat
* its own :not(:empty) visibility check) on every page, not just admin
* routes -- attach the fix globally rather than per-route.
*/
function figli_compta_ledger_page_attachments(array &$attachments) {
$attachments['#attached']['library'][] = 'figli_compta_ledger/admin_chrome';
}
/**
* Implements hook_help().
*/