import { PERMISSIONS, type Permission } from '@sport/types'; /** * The sidebar is derived from the same permission catalog the API guards use. * * An operator who cannot read orders never sees an Orders link, so the UI has * no dead ends. This is presentation only — hiding a link is not authorization. * The API re-checks every request, because a hidden link is one devtools * inspection away from being visible. * * Labels are message keys rather than strings: the sidebar is the most visible * surface in the admin, and hard-coding English here would have made the * language switcher look broken. */ export interface NavItem { href: string; /** Key into the `pages` message namespace. */ labelKey: string; permission: Permission; } export interface NavSection { /** Key into the `common.sections` message namespace. */ titleKey: 'catalog' | 'sales' | 'marketing' | 'settings'; items: NavItem[]; } export const NAVIGATION: NavSection[] = [ { titleKey: 'catalog', items: [ { href: '/products', labelKey: 'products', permission: PERMISSIONS.PRODUCT_READ }, { href: '/categories', labelKey: 'categories', permission: PERMISSIONS.CATEGORY_READ }, { href: '/collections', labelKey: 'collections', permission: PERMISSIONS.COLLECTION_READ }, { href: '/brands', labelKey: 'brands', permission: PERMISSIONS.BRAND_READ }, { href: '/inventory', labelKey: 'inventory', permission: PERMISSIONS.INVENTORY_READ }, { href: '/media', labelKey: 'media', permission: PERMISSIONS.MEDIA_READ }, ], }, { titleKey: 'sales', items: [ { href: '/orders', labelKey: 'orders', permission: PERMISSIONS.ORDER_READ }, { href: '/customers', labelKey: 'customers', permission: PERMISSIONS.CUSTOMER_READ }, ], }, { titleKey: 'marketing', items: [ // One entry, not "Promotions" + "Coupons" — see ADR-0020. { href: '/discounts', labelKey: 'discounts', permission: PERMISSIONS.PROMOTION_MANAGE }, { href: '/reviews', labelKey: 'reviews', permission: PERMISSIONS.REVIEW_MODERATE }, { href: '/cms', labelKey: 'cms', permission: PERMISSIONS.CMS_READ }, ], }, { titleKey: 'settings', items: [ { href: '/settings/users', labelKey: 'users', permission: PERMISSIONS.USER_READ }, { href: '/settings/roles', labelKey: 'roles', permission: PERMISSIONS.ROLE_READ }, ], }, ];