import type { CollectionConfig } from "payload"; import { isAdmin, isAdminFieldLevel } from "@/access"; export const Users: CollectionConfig = { slug: "users", labels: { singular: "Benutzer:in", plural: "Benutzer:innen", }, admin: { useAsTitle: "name", defaultColumns: ["name", "email", "role"], description: "Zugänge für den geschützten Admin-Bereich.", }, auth: { // Payload shows a "create first user" screen automatically when this // collection is empty, bypassing normal access control just for that // one-time setup — no hardcoded default password is ever needed. maxLoginAttempts: 5, lockTime: 10 * 60 * 1000, }, access: { read: isAdmin, create: isAdmin, update: isAdmin, delete: isAdmin, }, fields: [ { name: "name", type: "text", label: "Name", required: true, }, { name: "role", type: "select", label: "Rolle", required: true, defaultValue: "admin", // Only "admin" exists today; add further roles here later and extend // the checks in access/index.ts to match. options: [{ label: "Administrator:in", value: "admin" }], access: { update: isAdminFieldLevel, }, }, { name: "calendarFeedTokenHash", type: "text", // Only ever set by /api/admin/calendar-feed/regenerate (see // lib/calendar/feedToken.ts) — never exposed or directly settable via // any API, so the plaintext token is never retrievable again after // it's shown once at generation time. access: { create: () => false, read: () => false, update: () => false }, admin: { hidden: true }, index: true, }, // "email" and "password" are added automatically by `auth: true`-style config. ], };