feat: per-user module access, classification watchlists, watchlist persistence & move

**Module access control (admin)**
- Added modules column to users table (JSON array of allowed module keys)
- auth.me returns modules; admin.setUserModules/disableUser/enableUser/deleteUser procedures
- UserActions dropdown with Reset Password, Manage Modules, Disable/Enable, Delete
- useFeatureAccess hook + FeatureGate component for page-level gating
- SidebarNav, CommandPalette, MobileTabNav filter by modules

**Classification watchlists (auto-generated sector/thematic/style/region)**
- watchlists schema: added kind, class_key, class_label columns
- materializeClassificationWatchlists(): lazy idempotent materialization of system lists from Yahoo sector data
- 11 GICS sector lists, Semiconductors, Biotech thematic lists, Small Cap style, Intl region
- Materialization triggered on listWatchlists + addSymbol/removeSymbol/add
- Sector thematic filter uses industry keywords (semiconductors, biotech) to avoid misclassification
- Symbol overrides fixed: IREN removed from SMH theme, bitcoin miners XLE->XLK, SLNH added as Technology

**Watchlist persistence & move**
- active-watchlist-store.ts: Zustand persist store mirroring active-symbol-store pattern
- moveSymbol procedure: removes from source, adds to target (idempotent, preserves empty lists)
- Action menu (⋯) per row: Move to + Remove, click-outside close
- Active watchlist survives navigation and page reloads

**List protections**
- default list: non-deletable, non-renamable, keeps empty row when pruned
- System lists (sector/thematic etc.): read-only, add form hidden, no remove/move/delete

**Per-user module restrictions**
- ProtectedProcedure blocks non-active users
- deleteUser refuses self-delete and last-admin-delete, cleans halt_state manually
- Module gating on execution/analytics pages, sidebar, command palette, mobile nav

Also fixed: schema.sql index moved to migration, materialize DB column fixes, test updates.
This commit is contained in:
Investor Flow Build
2026-07-25 11:38:23 -04:00
parent 63d9f80c09
commit 7492317ebb
27 changed files with 1187 additions and 387 deletions
+6 -29
View File
@@ -1,32 +1,9 @@
# Handoff pointer (updated 2026-07-18)
# Handoff pointer (updated 2026-07-23)
This file previously held a 2026-06-30 multi-agent orchestrator snapshot. That snapshot is **obsolete**.
Full handoff saved externally — not in repo.
## Read these instead
1. **`docs/FUNCTIONAL_DESIGN.md`** — what is Live / Backend-ready / UI-local / Stub / Missing
2. **`docs/TECH_DESIGN.md`** — stack, tRPC map, engines, schema debt, test counts
3. **`CONTEXT.md`** — domain glossary (not status)
4. **Obsidian** `investor-flow.md` — session orientation wiki
## Active gap tasks (created 2026-07-18)
| Priority | Task |
|----------|------|
| P0 | `fix-macro-commentary-tests` |
| P0 | `wire-sizing-risk-trpc-m20` |
| P1 | `persist-trade-plan-execution-loop` |
| P1 | `frontend-api-client-coverage` |
| P1 | `wire-emotion-logger-backend` |
| P2 | `strategy-lab-backtest-ui` |
| P2 | `screener-ui-filter-strategy` |
| P2 | `thesis-monitor-derisking-ui` |
| P2 | `options-convexity-sleeve-ui` |
| P3 | `reports-research-note-ui` |
| P3 | `schema-strategies-dedupe` |
## Quick verify
```bash
cd app/server && npm test # expect 2 known MacroRegime failures until P0 fixed
```
Read /tmp/handoff-investor-flow-20260723.md for full context
```
Short version: Phase 5 alert UI done, queue errors fixed, automaton removed. See docs/ for as-built status.