export function getPrimaryUserRole( userRoles: string | null | undefined, fallback = "User", ): string { return userRoles?.split(",")[0]?.trim() || fallback; } export function isAdminUser(userRoles: string | null | undefined): boolean { return hasUserRole(userRoles, "admin"); } export function hasUserRole(userRoles: string | null | undefined, expectedRole: string): boolean { if (!userRoles) { return false; } const normalizedExpectedRole = expectedRole.trim().toLowerCase(); return userRoles .split(",") .map((role) => role.trim().toLowerCase()) .includes(normalizedExpectedRole); } /** * SH-336's `viewAllDispatchersOnDashboard` permission. The codebase has no * permission model, so it is derived from role: Admin and Scheduler may pick any * dispatcher (or the whole company) on the Dashboard; a Dispatcher may not and * is locked to their own work orders. Unknown roles default to the restrictive * (Dispatcher) behaviour so no one accidentally gains a company-wide view. */ export function canViewAllDispatchersOnDashboard(userRoles: string | null | undefined): boolean { if (!userRoles) { return false; } const roles = userRoles.split(",").map((role) => role.trim().toLowerCase()); return roles.includes("admin") || roles.includes("scheduler"); } /** * Site deletion is limited to Admin and Scheduler (the server enforces the DeleteSites team * permission; this only hides the control from roles that would get a 403). */ export function canDeleteSites(userRoles: string | null | undefined): boolean { return hasUserRole(userRoles, "admin") || hasUserRole(userRoles, "scheduler"); }