- Customer accounts now require email verification (hashed, single-use, time-limited tokens) before they can request/confirm bookings, with resend flows on login/account/booking widget and rate limiting. - Admins get a private, rotatable iCalendar (ICS) subscription feed of their confirmed bookings and public events, timezone-correct for Europe/Berlin including DST, never exposing meeting passwords. - Adds a full SEO layer: per-page canonical/OG/Twitter metadata with CMS-editable overrides and content-derived fallbacks, a dynamic sitemap.xml and robots.txt driven by real published content, JSON-LD (Organization/LocalBusiness, WebSite, WebPage, BreadcrumbList, Service, Event, BlogPosting) that never fabricates data, and a CMS-managed redirect table for changed slugs. - Global ANOUMA-naming audit: the brand name is never used to label personal account/calendar areas anywhere in the app, CMS, or emails. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
62 lines
1.8 KiB
TypeScript
62 lines
1.8 KiB
TypeScript
import type { CollectionConfig } from "payload";
|
|
import { isAdmin, isAdminFieldLevel } from "@/access";
|
|
|
|
export const Users: CollectionConfig = {
|
|
slug: "users",
|
|
labels: {
|
|
singular: "Benutzer:in",
|
|
plural: "Benutzer:innen",
|
|
},
|
|
admin: {
|
|
useAsTitle: "name",
|
|
defaultColumns: ["name", "email", "role"],
|
|
description: "Zugänge für den geschützten Admin-Bereich.",
|
|
},
|
|
auth: {
|
|
// Payload shows a "create first user" screen automatically when this
|
|
// collection is empty, bypassing normal access control just for that
|
|
// one-time setup — no hardcoded default password is ever needed.
|
|
maxLoginAttempts: 5,
|
|
lockTime: 10 * 60 * 1000,
|
|
},
|
|
access: {
|
|
read: isAdmin,
|
|
create: isAdmin,
|
|
update: isAdmin,
|
|
delete: isAdmin,
|
|
},
|
|
fields: [
|
|
{
|
|
name: "name",
|
|
type: "text",
|
|
label: "Name",
|
|
required: true,
|
|
},
|
|
{
|
|
name: "role",
|
|
type: "select",
|
|
label: "Rolle",
|
|
required: true,
|
|
defaultValue: "admin",
|
|
// Only "admin" exists today; add further roles here later and extend
|
|
// the checks in access/index.ts to match.
|
|
options: [{ label: "Administrator:in", value: "admin" }],
|
|
access: {
|
|
update: isAdminFieldLevel,
|
|
},
|
|
},
|
|
{
|
|
name: "calendarFeedTokenHash",
|
|
type: "text",
|
|
// Only ever set by /api/admin/calendar-feed/regenerate (see
|
|
// lib/calendar/feedToken.ts) — never exposed or directly settable via
|
|
// any API, so the plaintext token is never retrievable again after
|
|
// it's shown once at generation time.
|
|
access: { create: () => false, read: () => false, update: () => false },
|
|
admin: { hidden: true },
|
|
index: true,
|
|
},
|
|
// "email" and "password" are added automatically by `auth: true`-style config.
|
|
],
|
|
};
|