Skip to content

Add entry requirements and overrides to attendee logs - #66

Open
travismolick wants to merge 5 commits into
mainfrom
feature/attendee-log-reg-levels
Open

travismolick wants to merge 5 commits into
mainfrom
feature/attendee-log-reg-levels

Conversation

@travismolick

@travismolick travismolick commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Attendee logs can now restrict who gets logged as an attendee. Admins set optional requirements per log, and an attendee is allowed in if they meet any of them:

  • Registration level: the attendee's ConCat registration product matches a selected level (by product name or ID, case-insensitive). Levels are picked from a list built from ConCat registrations, cached for six hours, with a reload button.
  • Staff or above: the attendee's Tracker role is Staff, Lead, Manager, or Admin.
  • Minimum volunteer hours: the attendee has earned at least the set number of hours (1 or more, including bonuses) for the log's event. Denial messages show exact volunteer hours only to users who can override them.

Requirements based on Tracker data are checked first, so ConCat is only contacted when a registration level must be checked or the badge doesn't belong to a known user yet.

Overrides

A denied attendee can be let in anyway with Allow Anyway, which records who approved it and an optional reason. Managers and admins can always override; each log can also allow its gatekeepers to. Overrides are shown under the attendee's name and included in the attendee log export.

Denial messages show an attendee's exact volunteer hours only to users who can override the denial; everyone else sees the required number of hours.

The reason field is never focused automatically, it and the Allow Anyway button ignore Enter, and reasons containing long numbers are rejected, so a badge scanned at the wrong moment can't submit an override.

Banned users

Banned users are denied on every attendee log, including logs without requirements. The denial lists the ban alongside any requirement they also fail. Only managers and admins can override a ban, even on logs that let gatekeepers override other denials.
(See link)

Other changes

  • The attendee log export adds Overridden By and Override Reason columns, and escapes text that a spreadsheet would treat as a formula (all formats, including CSV).
  • If ConCat can't be reached, unknown badges can't be logged and known users get a clear denial, which can be overridden. A badge with no ConCat registration is reported as such.
  • The wiki architecture page and README describe both features.

Database

Two migrations, both nullable or defaulted, so existing logs keep working unchanged apart from the ban rule:

  • attendee_logs: allowed_registration_levels (json), allow_staff (bool), min_volunteer_hours (decimal 5,2), gatekeepers_can_override (bool)
  • attendee_log_user: overridden_by_id (nullable FK to users, null on delete), override_reason (string 255)

Behavior change

Banned users can no longer be logged into attendee logs without requirements unless a manager or admin overrides it.
(See link)

Testing

  • 48 feature tests in tests/Feature/AttendeeLogEntryRequirementsTest.php, covering each requirement, overrides and permissions, bans, ConCat failures, validation, and the export (xlsx and CSV).
  • Tested manually against the dev environment with test data, and against a copy of production data with read-only ConCat.

Attendee logs can now restrict who gets logged as an attendee. An attendee
is allowed in if they meet any of the requirements that are set:

- a ConCat registration level, matched by product name or ID
- a Tracker role of Staff or above
- a minimum number of earned volunteer hours for the log's event

Admins configure the requirements on the log page. The registration levels
to choose from are built from ConCat registrations and cached for six
hours, with a button to reload them. Requirements based on Tracker data
are checked first so ConCat is only contacted when necessary.
A denied attendee can be let in anyway with an override, which records the
user that approved it and an optional reason. Managers and admins can always
override denials, and each log can also allow its gatekeepers to.

Overrides are shown under the attendee's name in the log and included in
the attendee log export. The export escapes text that a spreadsheet would
treat as a formula. The override reason field is never focused
automatically and ignores Enter, and reasons containing long numbers are
rejected, so a badge scanned at the wrong moment can't submit an override.
Banned users are now denied on every attendee log, including logs without
entry requirements. The denial lists the ban alongside any requirement the
user also fails, and only managers and admins can override it, even on
logs that let gatekeepers override other denials.

Denial messages now show an attendee's exact volunteer hours only to users
that can override the denial. Everyone else sees the required number of
hours instead.
Describe entry requirements, overrides, and how banned users are handled
in the architecture wiki, and list both features in the README.
@travismolick
travismolick requested a review from a team October 2, 2026 22:40
@travismolick travismolick self-assigned this Oct 2, 2026
@travismolick travismolick added documentation Improvements or additions to documentation enhancement New feature or request labels Oct 2, 2026
Tracker's banned role is a volunteer ban, and a user banned from
volunteering can still be a registered attendee, so attendee logs no
longer check it. Banned users are logged the same way as on main.

Denial messages still show exact volunteer hours only to users who can
override them.
@travismolick

Copy link
Copy Markdown
Contributor Author

I've removed the banned-user check from this PR (910dc11).

Tracker's Banned role is a volunteer ban, and someone banned from volunteering can still be a registered attendee (for example, a Super Sponsor at a Super Sponsor event). Denying them on every attendee log was wrong, so attendee logs no longer look at the Banned role, the same as on main. Volunteer bans and ConCat registration bans will be handled later as a separate feature.

Everything else in the description still applies, except:

  • Ignore the "Banned users" and "Behavior change" sections.
  • Denial messages show exact volunteer hours only to users who can override the denial (this belongs under Overrides).
  • Test count is now 42.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants