Tableau de Bord
Users and Rights
Owner role management and permanent cleanup of non-owner test/user accounts.
Current rights overview
| Role | Read / browse | Catalogue contribution | AI | Images | Shopping Trips | Pending Approval | Reviews | Administration |
|---|---|---|---|---|---|---|---|---|
| Public (not logged in) | Accepted public catalogue | No | No | Published images only | No | No | Read accepted reviews | No |
| Viewer | Accepted public catalogue | No catalogue changes | No | Published images only | No | No | Add own review; accepted directly | No |
| Contributor, Priv. Students | Accepted catalogue + own moderated submissions where exposed | EANs and direct Prices are pending; may edit own EANs; catalogue helper creation where exposed | Own EANs only | Upload staged EAN images; publication requires Editor/Owner approval | Create and AI-process own trips; submit complete trip for approval | No administrator queue; own work remains pending until reviewed | Add own review; accepted directly | No TDB administration |
| Editor | Accepted + pending/rejected moderated catalogue content | Create/edit catalogue content directly | Full rights (1) | Full rights (2) | Create/process own trips; review, approve or return Contributor trips | Full Pending Approval queue and moderation | Add reviews; moderate pending review rows | Editor/content tools; no user, generic database or backup administration |
| Owner | Everything | Everything | Full rights (1) | Full rights | Full workflow and approval | Full queue and moderation | Full access | Users/roles, generic database, backups and owner-only destructive tools |
(1) Editors and Owners can AI-process only Shopping Trips they created themselves.
(2) Editors have full catalogue/EAN image rights, but do not have Owner-only Shopping Trip image maintenance.
This matrix describes the application as currently implemented. RLS, Storage policies, RPC role checks and API checks remain the actual protection. Public is not a stored profile role; viewer, contributor, editor and owner are stored in profiles.app_role.
Moderation and workflow details
| Workflow | Viewer | Contributor, Priv. Students | Editor | Owner |
|---|---|---|---|---|
| EAN submission | — | Pending; own EAN remains editable and may use AI | Accepted directly | Accepted directly |
| Direct Price entry | — | Pending | Accepted directly | Accepted directly |
| EAN image upload | — | Staged privately; Editor/Owner publishes or rejects | Direct catalogue-image administration | Direct catalogue-image administration |
| Shopping Trip | — | Own trip + AI; submit whole final review workspace as pending | Own trip + AI; approve/return Contributor whole trips | Own trip + AI; approve/return Contributor whole trips |
| Shopping Trip Prices | — | Not created at submission time | Whole-trip approval creates accepted Prices | Whole-trip approval creates accepted Prices |
| Pending Approval queue | — | — | Shopping Trips, EANs, Prices, Ingredients, Nutrients, Reviews and staged Images | Shopping Trips, EANs, Prices, Ingredients, Nutrients, Reviews and staged Images |
| Reviews | Read accepted | Own review accepted directly | Accepted directly; may moderate pending rows | Accepted directly; may moderate pending rows |
| Image destructive actions | — | — | Allowed inside image-admin workflows | Allowed |
| Generic destructive/admin tools | — | — | — | Owner only |
Contributor Shopping Trips are moderated as one complete trip, not as a collection of disconnected pending Price rows. The Editor/Owner opens the final Shopping Trip workspace with the receipt and item context, then approves the whole trip or returns it for revision. Contributor EAN images are staged rather than publicly attached until approval.
Checking owner access...
| Display name | Role | Legacy WP id | Created | Updated | Actions |
|---|