Replaces the demo module behind the team directory and the employee record with scoped queries, and adds contracts, amendments, work permits and the forfait-jours fields. Writing the end-to-end test exposed a modelling error worth naming: first and last names lived only on User, so an employee without an application account had no name at all — the directory rendered "— Salarié E0007". Most sales staff never sign in, and the personnel register requires their name, so the name belongs to the record, not to the login. Moved to EmployeeProfile with a data migration that carries the existing names down from User. Contract rules are pure functions tested at the boundaries. The case that matters is an open-ended contract: a CDI with no end date overlaps every later period, which a naive comparison of two date pairs misses, and two overlapping active contracts would count one employee twice in payroll. The check runs inside the transaction, not only in the form. Forfait jours is refused without a written individual agreement and a dated employee consent: without them the arrangement is unenforceable, and enabling it would also switch off every weekly-duration control. Salary and bank details are not merely hidden when the capability is missing — they are never loaded. A field absent from the response cannot leak through HTML, a log or an error message. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
283 lines
8.8 KiB
TypeScript
283 lines
8.8 KiB
TypeScript
import 'dotenv/config';
|
|
|
|
import { PrismaPg } from '@prisma/adapter-pg';
|
|
import { PrismaClient } from '@prisma/client';
|
|
import { hash } from '@node-rs/argon2';
|
|
|
|
import {
|
|
DEFAULT_ROLE_PERMISSIONS,
|
|
PERMISSION_DEFINITIONS,
|
|
SYSTEM_ROLES,
|
|
} from '../src/domain/access/permissions';
|
|
|
|
/**
|
|
* Jeu de données de départ — PLAN.md §11.
|
|
*
|
|
* **Entièrement fictif.** Deux établissements, des équipes, et les rôles
|
|
* fournis. Le mot de passe de démonstration n'a de sens qu'en développement ;
|
|
* il est refusé si NODE_ENV vaut production.
|
|
*/
|
|
|
|
const DEMO_PASSWORD = 'planflow-demo-2026';
|
|
|
|
const adapter = new PrismaPg({
|
|
connectionString: process.env.DATABASE_URL ?? '',
|
|
});
|
|
const prisma = new PrismaClient({ adapter });
|
|
|
|
async function main() {
|
|
if (process.env.NODE_ENV === 'production') {
|
|
throw new Error(
|
|
'Le seed installe un compte de démonstration : refusé en production.',
|
|
);
|
|
}
|
|
|
|
console.log('→ Capacités');
|
|
for (const permission of PERMISSION_DEFINITIONS) {
|
|
await prisma.permission.upsert({
|
|
where: { code: permission.code },
|
|
update: { category: permission.category, label: permission.label },
|
|
create: permission,
|
|
});
|
|
}
|
|
console.log(` ${PERMISSION_DEFINITIONS.length} capacités`);
|
|
|
|
console.log('→ Compte');
|
|
const account = await prisma.account.upsert({
|
|
where: { id: 'demo-account' },
|
|
update: {},
|
|
create: {
|
|
id: 'demo-account',
|
|
name: 'Maison Rivage',
|
|
siren: '000000000',
|
|
apeCode: '4759B',
|
|
collectiveAgreementId: '1517',
|
|
},
|
|
});
|
|
|
|
console.log('→ Rôles');
|
|
const roleIds = new Map<string, string>();
|
|
for (const role of SYSTEM_ROLES) {
|
|
const created = await prisma.role.upsert({
|
|
where: { accountId_key: { accountId: account.id, key: role.key } },
|
|
update: { name: role.name },
|
|
create: {
|
|
accountId: account.id,
|
|
key: role.key,
|
|
name: role.name,
|
|
isSystem: true,
|
|
},
|
|
});
|
|
roleIds.set(role.key, created.id);
|
|
|
|
const codes = DEFAULT_ROLE_PERMISSIONS[role.key];
|
|
const permissions = await prisma.permission.findMany({
|
|
where: { code: { in: codes } },
|
|
});
|
|
|
|
await prisma.rolePermission.deleteMany({ where: { roleId: created.id } });
|
|
await prisma.rolePermission.createMany({
|
|
data: permissions.map((permission) => ({
|
|
roleId: created.id,
|
|
permissionId: permission.id,
|
|
})),
|
|
skipDuplicates: true,
|
|
});
|
|
console.log(` ${role.name} — ${permissions.length} capacités`);
|
|
}
|
|
|
|
console.log('→ Établissements');
|
|
const locations = [
|
|
{ id: 'loc-nantes', name: 'Nantes Atlantis' },
|
|
{ id: 'loc-rennes', name: 'Rennes Alma' },
|
|
];
|
|
for (const location of locations) {
|
|
await prisma.location.upsert({
|
|
where: { id: location.id },
|
|
update: { name: location.name },
|
|
create: {
|
|
id: location.id,
|
|
accountId: account.id,
|
|
name: location.name,
|
|
employerContributionRate: 42,
|
|
},
|
|
});
|
|
for (const [index, team] of ['Vente', 'Caisse', 'Réserve'].entries()) {
|
|
await prisma.team.upsert({
|
|
where: { id: `${location.id}-${index}` },
|
|
update: {},
|
|
create: {
|
|
id: `${location.id}-${index}`,
|
|
accountId: account.id,
|
|
locationId: location.id,
|
|
name: team,
|
|
position: index,
|
|
},
|
|
});
|
|
}
|
|
}
|
|
|
|
console.log('→ Comptes utilisateurs');
|
|
const passwordHash = await hash(DEMO_PASSWORD, {
|
|
memoryCost: 19_456,
|
|
timeCost: 2,
|
|
parallelism: 1,
|
|
});
|
|
|
|
const people = [
|
|
{ email: 'direction@example.test', firstName: 'Camille', lastName: 'Ferrand', role: 'owner', all: true },
|
|
{ email: 'manager.nantes@example.test', firstName: 'Jonas', lastName: 'Meyer', role: 'manager', all: false },
|
|
{ email: 'manager.rennes@example.test', firstName: 'Inès', lastName: 'Bakhti', role: 'manager', all: false },
|
|
{ email: 'salarie@example.test', firstName: 'Rémi', lastName: 'Chartier', role: 'employee', all: false },
|
|
];
|
|
|
|
for (const [index, person] of people.entries()) {
|
|
const user = await prisma.user.upsert({
|
|
where: { email: person.email },
|
|
// Remet le compteur d'échecs à zéro : sans cela, des exécutions
|
|
// répétées des tests finissent par verrouiller le compte au bout de
|
|
// huit tentatives, et l'échec suivant est incompréhensible.
|
|
update: { failedAttempts: 0, lockedUntil: null, passwordHash },
|
|
create: {
|
|
email: person.email,
|
|
firstName: person.firstName,
|
|
lastName: person.lastName,
|
|
passwordHash,
|
|
},
|
|
});
|
|
|
|
const membership = await prisma.membership.upsert({
|
|
where: {
|
|
accountId_employeeNumber: {
|
|
accountId: account.id,
|
|
employeeNumber: `E${String(index + 1).padStart(4, '0')}`,
|
|
},
|
|
},
|
|
update: { userId: user.id, status: 'ACTIVE' },
|
|
create: {
|
|
accountId: account.id,
|
|
userId: user.id,
|
|
roleId: roleIds.get(person.role) as string,
|
|
employeeNumber: `E${String(index + 1).padStart(4, '0')}`,
|
|
status: 'ACTIVE',
|
|
},
|
|
});
|
|
|
|
await prisma.membershipScope.deleteMany({
|
|
where: { membershipId: membership.id },
|
|
});
|
|
await prisma.membershipScope.create({
|
|
data: {
|
|
accountId: account.id,
|
|
membershipId: membership.id,
|
|
allLocations: person.all,
|
|
locationId: person.all
|
|
? null
|
|
: person.email.includes('rennes')
|
|
? 'loc-rennes'
|
|
: 'loc-nantes',
|
|
},
|
|
});
|
|
console.log(` ${person.email} — ${person.role}`);
|
|
}
|
|
|
|
console.log('→ Contrats et dossiers');
|
|
const contractSpecs = [
|
|
{ number: 'E0001', type: 'CDI', hours: 39, forfait: false, location: 'loc-nantes' },
|
|
{ number: 'E0002', type: 'CDI', hours: 0, forfait: true, location: 'loc-nantes' },
|
|
{ number: 'E0003', type: 'CDI', hours: 35, forfait: false, location: 'loc-rennes' },
|
|
{ number: 'E0004', type: 'CDD', hours: 24, forfait: false, location: 'loc-nantes' },
|
|
] as const;
|
|
|
|
for (const spec of contractSpecs) {
|
|
const membership = await prisma.membership.findUnique({
|
|
where: {
|
|
accountId_employeeNumber: {
|
|
accountId: account.id,
|
|
employeeNumber: spec.number,
|
|
},
|
|
},
|
|
});
|
|
if (!membership) continue;
|
|
|
|
const holder = membership.userId
|
|
? await prisma.user.findUnique({ where: { id: membership.userId } })
|
|
: null;
|
|
|
|
await prisma.employeeProfile.upsert({
|
|
where: { membershipId: membership.id },
|
|
update: {},
|
|
create: {
|
|
membershipId: membership.id,
|
|
accountId: account.id,
|
|
firstName: holder?.firstName ?? 'Prénom',
|
|
lastName: holder?.lastName ?? 'À compléter',
|
|
city: 'Nantes',
|
|
phone: '00 00 00 00 00',
|
|
},
|
|
});
|
|
|
|
const existing = await prisma.userContract.findFirst({
|
|
where: { membershipId: membership.id },
|
|
});
|
|
if (existing) continue;
|
|
|
|
await prisma.userContract.create({
|
|
data: {
|
|
accountId: account.id,
|
|
membershipId: membership.id,
|
|
locationId: spec.location,
|
|
contractType: spec.type,
|
|
startDate: new Date('2024-01-08'),
|
|
workTimeArrangement: spec.forfait ? 'FORFAIT_JOURS' : 'HOURLY',
|
|
weeklyHours: spec.forfait ? 0 : spec.hours,
|
|
forfaitDaysPerYear: spec.forfait ? 218 : null,
|
|
forfaitAgreementRef: spec.forfait ? 'CONV-2024-002' : null,
|
|
forfaitAgreedAt: spec.forfait ? new Date('2024-01-05') : null,
|
|
monthlySalary: 2100,
|
|
},
|
|
});
|
|
}
|
|
console.log(` ${contractSpecs.length} contrats`);
|
|
|
|
console.log('→ Durées de conservation');
|
|
const retention = [
|
|
['Shift', 12, 'creation', 'Décompte des horaires : 1 an minimum (matrice n° 21).'],
|
|
['ForfaitDayEntry', 36, 'creation', 'Décompte des jours de forfait : 3 ans minimum.'],
|
|
['UserContract', 60, 'contract_end', 'Pièces contractuelles : 5 ans.'],
|
|
['PersonnelRegister', 60, 'employee_departure', 'Registre du personnel : 5 ans après le départ.'],
|
|
['PayrollVariable', 72, 'period_end', "Éléments d'assiette transmis à Silae : 6 ans."],
|
|
] as const;
|
|
|
|
for (const [objectType, durationMonths, startPoint, justification] of retention) {
|
|
await prisma.retentionPolicy.upsert({
|
|
where: {
|
|
accountId_objectType_effectiveFrom: {
|
|
accountId: account.id,
|
|
objectType,
|
|
effectiveFrom: new Date('2026-01-01'),
|
|
},
|
|
},
|
|
update: { durationMonths, startPoint, justification },
|
|
create: {
|
|
accountId: account.id,
|
|
objectType,
|
|
durationMonths,
|
|
startPoint,
|
|
justification,
|
|
effectiveFrom: new Date('2026-01-01'),
|
|
},
|
|
});
|
|
}
|
|
console.log(` ${retention.length} politiques`);
|
|
|
|
console.log(`\nMot de passe de démonstration : ${DEMO_PASSWORD}`);
|
|
}
|
|
|
|
main()
|
|
.catch((error) => {
|
|
console.error(error);
|
|
process.exitCode = 1;
|
|
})
|
|
.finally(() => prisma.$disconnect());
|