Repository navigation
Add entry requirements and overrides to attendee logs - #66
Open
travismolick wants to merge 5 commits into
Open
travismolick wants to merge 5 commits into
travismolick wants to merge 5 commits into
Conversation
Attendee logs can now restrict who gets logged as an attendee. An attendee is allowed in if they meet any of the requirements that are set: - a ConCat registration level, matched by product name or ID - a Tracker role of Staff or above - a minimum number of earned volunteer hours for the log's event Admins configure the requirements on the log page. The registration levels to choose from are built from ConCat registrations and cached for six hours, with a button to reload them. Requirements based on Tracker data are checked first so ConCat is only contacted when necessary.
A denied attendee can be let in anyway with an override, which records the user that approved it and an optional reason. Managers and admins can always override denials, and each log can also allow its gatekeepers to. Overrides are shown under the attendee's name in the log and included in the attendee log export. The export escapes text that a spreadsheet would treat as a formula. The override reason field is never focused automatically and ignores Enter, and reasons containing long numbers are rejected, so a badge scanned at the wrong moment can't submit an override.
Banned users are now denied on every attendee log, including logs without entry requirements. The denial lists the ban alongside any requirement the user also fails, and only managers and admins can override it, even on logs that let gatekeepers override other denials. Denial messages now show an attendee's exact volunteer hours only to users that can override the denial. Everyone else sees the required number of hours instead.
Describe entry requirements, overrides, and how banned users are handled in the architecture wiki, and list both features in the README.
Tracker's banned role is a volunteer ban, and a user banned from volunteering can still be a registered attendee, so attendee logs no longer check it. Banned users are logged the same way as on main. Denial messages still show exact volunteer hours only to users who can override them.
Contributor
Author
|
I've removed the banned-user check from this PR (910dc11). Tracker's Banned role is a volunteer ban, and someone banned from volunteering can still be a registered attendee (for example, a Super Sponsor at a Super Sponsor event). Denying them on every attendee log was wrong, so attendee logs no longer look at the Banned role, the same as on main. Volunteer bans and ConCat registration bans will be handled later as a separate feature. Everything else in the description still applies, except:
|
NetworkInterface
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Attendee logs can now restrict who gets logged as an attendee. Admins set optional requirements per log, and an attendee is allowed in if they meet any of them:
Requirements based on Tracker data are checked first, so ConCat is only contacted when a registration level must be checked or the badge doesn't belong to a known user yet.
Overrides
A denied attendee can be let in anyway with Allow Anyway, which records who approved it and an optional reason. Managers and admins can always override; each log can also allow its gatekeepers to. Overrides are shown under the attendee's name and included in the attendee log export.
Denial messages show an attendee's exact volunteer hours only to users who can override the denial; everyone else sees the required number of hours.
The reason field is never focused automatically, it and the Allow Anyway button ignore Enter, and reasons containing long numbers are rejected, so a badge scanned at the wrong moment can't submit an override.
Banned usersBanned users are denied on every attendee log, including logs without requirements. The denial lists the ban alongside any requirement they also fail. Only managers and admins can override a ban, even on logs that let gatekeepers override other denials.(See link)
Other changes
Database
Two migrations, both nullable or defaulted, so existing logs keep working unchanged apart from the ban rule:
attendee_logs:allowed_registration_levels(json),allow_staff(bool),min_volunteer_hours(decimal 5,2),gatekeepers_can_override(bool)attendee_log_user:overridden_by_id(nullable FK to users, null on delete),override_reason(string 255)Behavior changeBanned users can no longer be logged into attendee logs without requirements unless a manager or admin overrides it.(See link)
Testing
tests/Feature/AttendeeLogEntryRequirementsTest.php, covering each requirement, overrides and permissions, bans, ConCat failures, validation, and the export (xlsx and CSV).