Commit Graph

3 Commits

Author SHA1 Message Date
micko samawa cf4435580d final update web and mobile 2026-06-12 22:46:44 +07:00
micko samawa 6bad1aa7b2 feat: Implement admin-scoped data visibility and comprehensive authorization
- Add admin_id FK to kontrakans table
- Add authorization checks to KontrakanController (edit, update, destroy, bulkDestroy)
- Add authorization checks to BookingController (store, bulkDestroy)
- Fix EnsureRole middleware to use auth:admin guard
- Fix booking index stats to filter by admin ownership
- Add model relationships: Admin.kontrakans(), Admin.isSuperAdmin(), Admin.isAdmin()
- Ensure admin biasa sees only their data, super_admin sees all data
- Secure bulk delete operations with per-item admin validation
2026-05-25 14:00:20 +07:00
micko samawa 585d36fe09 feat: Separate admin and user tables for independent authentication
- Create new 'admins' table with role column (admin/super_admin)
- Create Admin model for admin authentication
- Add AdminSeeder with test data (super_admin, admin)
- Update config/auth.php with dual guards (web for users, admin for admins)
- Update AdminAuthController to use Admin model and 'admin' guard
- Remove role column from users table (users have no role)
- Update register validation messages in Indonesian
- Now same email can be used by user and admin (separate tables)
2026-05-18 20:50:22 +07:00