root (renamed from the default admin/admin account) keeps full, unrestricted access outside any role system. These three cover the actual associates: - user: read-only, 'access content' only -- can browse /lignes and /dashboard, nothing else. - editeur: 'access content' + create/edit any/delete any ligne_comptable content -- can enter and correct accounting lines, no site configuration. - admin: identical permission set to editeur for now (per instruction, actual config permissions to be scoped later). Left the pre-existing "administrator" (is_admin bypass -- too broad) and "content_editor" (generic Standard-recipe scaffolding, permissions unrelated to ligne_comptable) roles untouched but unused; worth pruning later if nothing ends up using them. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
15 lines
307 B
YAML
15 lines
307 B
YAML
uuid: d14de2f6-99a6-4c9a-8eed-c95f83b56607
|
|
langcode: en
|
|
status: true
|
|
dependencies:
|
|
config:
|
|
- user.role.editeur
|
|
module:
|
|
- user
|
|
id: user_remove_role_action.editeur
|
|
label: 'Remove the Éditeur role from the selected user(s)'
|
|
type: user
|
|
plugin: user_remove_role_action
|
|
configuration:
|
|
rid: editeur
|