feat(saas): Phase 3 — plan/seats/active model, ToS consent, signed expiring export

P3a: org carries plan/seats/active/created_at; create_user enforces seats + rejects
inactive org; verify blocks login for inactive orgs; PATCH /api/admin/orgs (super_admin)
updates plan/seats/active with audit. Fixed verify swallowing its AuthError.
P3b: export/token issues a 5-min HMAC one-time CSV link; export accepts ?token=.
P3c: setup requires accepted_terms (consent stored); Setup.vue consent checkbox.
All 8 backend suites pass. Rebuilt dist.
This commit is contained in:
Macky
2026-08-09 09:48:55 +07:00
parent 056753e8cb
commit 3d5c81fbd7
36 changed files with 230 additions and 64 deletions

View File

@@ -37,8 +37,8 @@ export const auth = reactive({
this.mustSetup = !!data.must_setup
return data.user
},
async finishSetup(email, password) {
const data = await api.setup({ username: this.user.username || this.user.id, email, password })
async finishSetup(email, password, acceptedTerms = false) {
const data = await api.setup({ username: this.user.username || this.user.id, email, password, accepted_terms: acceptedTerms })
this.user = data.user
this.mustSetup = false
return data.user