feat(users): admin promote/demote endpoints
POST /users/{id}/promote and /demote set a user's role (admin/user), admin-only
(403 otherwise). Mirrors the verify endpoints: SetRole use case + repo method,
validated role. Unit, admin-flow, and integration tests included.
This commit is contained in:
@@ -27,6 +27,8 @@ layers, dependencies pointing strictly inward:
|
||||
| GET | `/me` | Bearer JWT | Return the caller's own account |
|
||||
| POST | `/users/{id}/verify` | Bearer admin | Grant the trusted-contributor badge |
|
||||
| POST | `/users/{id}/unverify` | Bearer admin | Revoke the badge |
|
||||
| POST | `/users/{id}/promote` | Bearer admin | Set the user's role to admin |
|
||||
| POST | `/users/{id}/demote` | Bearer admin | Set the user's role back to user |
|
||||
|
||||
Two independent attributes live on an account:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user