Allow an event owner to add co-organizers who can scan tickets #50
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Right now only the account that owns the event's wallet can scan tickets at the door. Anyone else helping run the event has no way in — they land on the public event page and the only thing offered is a Buy button.
We want the organizer to be able to name additional accounts as co-organizers of an event. A co-organizer doesn't buy a ticket; when they open the event page they get the scanner instead.
Where the ownership check lives today
Both scanner paths resolve the caller to a wallet and require that wallet to own the event:
transport_rpcs.py—handle_events_ticket_registerandhandle_events_list_event_tickets:if event.wallet not in owned_wallet_ids: raise PermissionError("You do not own this event")views_api.pyEventDetailPage.vuedecides vialoadOwnedEvent()— it callsfetchMyEvents(invoiceKey)and looks for the event id in the result. An event the user co-organizes isn't in "my events", soownedLnbitsEventstays null and the scanner block never renders.So it's three places: storage for the co-organizer list, an authorization helper both scanner paths use, and something the webapp can ask "can I scan this?".
Sketch
extra.co_organizers, list of LNbits user ids).migrations_fork.pyif it needs a column.can_manage_event(event, user) -> bool, returning true for the wallet owner or a listed co-organizer. Both RPCs and both HTTP endpoints call it instead of the inlineevent.wallet not in owned_wallet_idscheck.fetchMyEventsmembership, which won't cover this. Needs either aco_organizerflag on the event payload or a small "can I scan this event" call, andEventDetailPage.vuegating the scanner on that instead ofownedLnbitsEvent.Open questions