feat: initialize project backend structure and document system specifications across all modules

This commit is contained in:
SonPhung
2026-07-24 09:05:41 +07:00
parent 506008c69f
commit 4534e4ecb8
74 changed files with 7989 additions and 44 deletions

View File

@@ -0,0 +1,243 @@
---
title: "OneAccess"
type: OpenSpec
status: Draft
---
# OneAccess
## Overview
1. OneAccess™ is the module for managing user access rights to OLS administration functions.
2. The Access control Management functions are comprised of:
* User Group definition
* User Profile set-up (defining user IDs for logging into the system).
* Permission Management setup 2 permission type: Particular user/ User Group.
1. Report permission
* To identify reports each Permission Group is allowed to access.
1. View filter Management
Every screen can be configured with a filter based on the value of fields in the screen (View Filter). The View Filter restricts which fields in which screens are displayed to users in a User Group. The View Filter can also be used to block the entire view from the users in a User Group.
**In phase 1, we are focusing on item #1 first and allow automation to approve when user/edit record.**
## User Group
### Business Requirement
1. The User Group module is utilized to categorize users who share identical permissions within OLS.
2. Use this screen to define the group to be assigned to a particular user or group of users. When adding a new user to the system, select this group for that user.
### Process Flow
=TBD=
### Trigger
1. A new user group needs to be defined.
2. An existing user group needs to be modified or the user needs to review the existing group to make any decision.
### Post Condition
1. Users have to have the access right on this screen to access this screen.
2. Depending on the users access rights, they can view/add/edit user group records.
### Wireframe
Please refer to the wireframe on the Figma.
### Business Rules
* + - * 1. The user group ID must be a unique value.
2. If the required user group has not been defined, click on the User group icon in the Main Menu to bring up the summary list as illustrated in section [Wireframe](#_Wireframe_18)
3. Click on Add button ([Image Removed]) in the screen to bring up the edit form; clicking on the MoreOutLined icon (⋮) then click on Edit icon (!) also brings up the same edit form. The edit form for User Group is illustrated in section [Wireframe](#_Wireframe_18).
4. Screen description:
| | | | |
| --- | --- | --- | --- |
| **Index** | **Field** | **Description** | **Data type** |
| **Genneral information** | | | |
| | User Group ID\*/ Id nhóm người dùng | The identify of user group | ~~X(20)~~ X(10) |
| | User group Name\*/ Tên nhóm người dung | The name of the user group For reference only | X(100) |
| | Description /Mô tả | Description for user group | X(200) |
| **Group users: List all active User Profile record are assigned to this group.** **This part is display when user click to view any active record only** | | | |
| | User ID\* / ID người dùng | The identify of the user who be long to the chosen group | Display |
| | User name\*/Tên người dung | The name of the user | Display |
| | Email \*/Địa chỉ email | Email | Display |
### Post Condition
* 1. The data is updated in the DB and relation screen (if needed).
### Exception Flow
1. Input data are not passed all validations and then user choose cancel the action then use case ends in failure.
## Permission Management
### Business requirement
1. The Permission Management module is used to maintain Access Rights Groups i.e. to define:
1. Which modules and functions can be accessed by users in a group, and
2. Which of the applicable actions can be performed by the users in each of the functions within each of the modules in the group:
| | | |
| --- | --- | --- |
| * + 1. Add | * + 1. Change | * + 1. View |
| * + 1. Delete | * + 1. Approve (or Reject) | * + 1. Copy |
| * + 1. View History | h. Save as Template | |
### Process Flow
TBD
### Trigger
* + 1. New user group to be defined then need to add permission to this group.
### Post-Conditions
1. Users have to have the access right on this screen in order to access this screen.
2. Depending on the users access rights, they can view/add/edit Permission Management records.
### Wireframe
Please refer to the wireframe on the Figma.
### Business Rules
* + - * 1. If permission required has not been defined, click on the Permission Management icon in the Main Menu to bring up the summary list as illustrated in the section [Wireframe](#_Wireframe_19)
2. Click on the Add button ([Image Removed]) in the screen to bring up the edit form; clicking on the MoreOutLined icon (⋮) and then clicking on the Edit icon (!) also brings up the same edit form. The edit form for Permission Management is illustrated in the section [Wireframe](#_Wireframe_19).
3. Screen description
| | | | |
| --- | --- | --- | --- |
| **Index** | **Field** | **Description** | **Data type** |
| **Step 1\*: General information/Thông tin Chung** | | | |
| | Role \*/Quyền | The unique identifier of the permission group. | ~~X(20)~~ X(10) |
| | Role Name\*/Tên nhóm quyền | Text describing the Permission Group Name, for user reference | X(100) |
| | Permission Type \*/Loại quyền | Drop down to select the following permission type: *Particular User* *User Group* | Drop-down Select one |
| | User/Người dùng | Condition field Drop-down list to select one or more users who can be accessed on all functions of this role. This field is only active and required when "Particular User" is selected in the previous step. | Drop-down Multiple select |
| | User group/ Nhóm người dung | Condition field Drop-down list to select only one group and all users under this group can be accessed on all functions of this role. This field is only active and required when this role is applicable to the user group type. | Drop-down Select one |
| | Description/ Mô tả | Text describing the Role, for user reference | X(200) |
| **Step 2**\*: **Permission Management** /Quản lí quyền | | | |
| | **Select Modules** A hierarchy of modules contains the list of functions available. Top-level module: The modules group Second level module: The specific module for each group. Allow the user to search the modules by entering the module name | | |
| | Select All/Chọn tất cả | Check/Uncheck to drag/drop all modules in the system into the permission part to configure the specific permission of the role. | Check box |
| | “Module Name” | Check/Uncheck to drag/drop this module permission part to configure the specific permission of the role. Checked/Unchecked on top level then all second level modules will be applicable as well. | Check box |
| | Search /Tìm kiếm | Users input their search keyword(s) into a designated search bar to find the module they're looking for. | Search feature |
| | **Permission /Quyền** **A list contains all selected modules in the previous step and the permission list applicable for each module.** **Note that: N/A =**Not Applicable will be defined in the master data and the user cant check/uncheck to allow/disallow the permission if this permission is not applicable. **The system allows the user to quickly add/delete one permission to all modules per each module group.** **Besides the system allows** to allow/disallow all available permissions for all modules that appeared in the “Permission” part | | |
| | Selected all/Chọn tất cả | Check/Uncheck to allow/disallow all available permissions for all modules that appeared in the “Permission” part. | Check box |
| | “Top-level module name” E.g: Customer Management | The name of the top-level selected module. Check/uncheck to allow/disallow all available permission for all second-level modules belonging to this module | Check box |
| | “Second level Module name” E.g: Card | The name of the second level selected module. Check/uncheck to allow/disallow all available permissions for the chosen module. | Check box |
| | “Second level Module name” E.g: Card | Click on the second level module to bring up the popup to define the permission of each field on the each screen. See more on “Acccess Right Fields” | Hyperlink |
| | View /Xem | This column contains one checkbox in each row corresponding to a function to which the View action is applicable. If checked, users in this role can view the data available in this function | Check box |
| | Create/Thêm mới | This column contains one checkbox in each row corresponding to a function to which the Create action is applicable. If checked, users in this role can create data in this function. If user have created permisson then user will have "Save as draft" role also | Check box |
| | Edit /Sửa | This column contains one checkbox in each row corresponding to a function to which the Edit action is applicable. If checked, users in this role can do "update" action in this function. | Check box |
| | Delete/Xóa | This column contains one checkbox in each row corresponding to a function to which the Delete action is applicable. If checked, users in this role can do "delete" action in this function. | Check box |
| | Copy /Sao chép | This column contains one checkbox in each row corresponding to a function to which the Copy action is applicable. If checked, users in this Role can coppy available data in this function | Check box |
| | Approve /Phê duyệt | This column contains one checkbox in each row corresponding to a function to which the Approve/Reject action are applicable. If checked, users in this role can do " approve/reject" action in this function | Check box |
| | History/Xem lịch sử | This column contains one checkbox in each row corresponding to a function to which the History action (i.e. to view earlier versions of the data in the activity log) is applicable. If checked, users in this role can view data history in this function. | Check box |
| | Template/Tạo biểu mẫu | This column contains one checkbox in each row corresponding to a function to which the "Save As Tempalte"action is applicable. If checked, users in this role can save record as a template and able to access to "template" tab in listing page | Check box |
| **Access rights field /Phần quyền chi tiết trường thông tin** | | | |
| | Access permission | The list available fields of chosen module | Display |
| | View/Xem | This column contains one checkbox in the each row corresponding to a function to which the “view” action is applicable. If checked, user in this role can view the field in the screen. | Check box |
| | Editable/Cho phép chỉnh sửa | This column contains one checkbox in the each row corresponding to a function to which the “Editable” action is applicable. If checked, user in this role can modify the value of this field in the screen. | Checkbox |
* When viewing any record, the system displays only the available permissions for this group.
### Post-Conditions
Record is automation approval.
Based on the permission the system will check and display available module/function of each user as following:
A = Set of Permission of role which are assigned directly to user
B= Set of Permission of Role which are assigned to permission group and user are in these permission group.
**Therefore: C= User permission = Combination of A and B.**
### Exception Flow
1. Input data are not passed all validations and then user choose cancel the action then use case ends in failure.
## User Profile
### Business requirement
The user profile defines user attributes and sets the date and time for allowing user access to system functions. User profile created will be used for login, and users, upon logging in, will be able to view a list of functions with specific operations set in the permission management section and will be associated with users through this function screen.
### Process Flow
N/A
### Trigger
* + 1. New account need to be defined.
2. Need to update information of any existing account in the system.
### Post-codition
1. Users have to have the access right on this screen in order to access this screen.
2. Depending on users access rights, they can view/add/edit User Profile records.
### Wireframe
Please refer to the wireframe in the Figma.
### Business Rules
* + - * 1. If the permission required has not been defined, click on the User Profile icon in the Main Menu to bring up the summary list as illustrated in the section [Wireframe](#_Wireframe_20).
2. Click on the Add button ([Image Removed]) in the screen to bring up the edit form; clicking on the MoreOutLined icon (⋮) and then clicking on the Edit icon (!) also brings up the same edit form. The edit form for the User Profile is illustrated in the section [Wireframe](#_Wireframe_20).
3. Screen description
| | | | |
| --- | --- | --- | --- |
| **Index** | **Field** | **Description** | **Data type** |
| **General information** | | | |
| | User ID\*/ ID người dùng | Unique user identifier, assigned by the user | X(10) |
| | User Name\*/Tên người dùng | Name of the user associated with the User ID | X(50) |
| | Password/Mật khẩu | Condition field This field is only active and required when creating a new user. The password must be strong enough. | X(50) |
| | Re-enter password/Nhập lại mật khẩu | Condition filed This field is only active and required when viewing any record. The re-enter password must be matched with the password. | X(50) |
| | Reset Password | Condition field This field is only active and required when updating the user profile record. Click to reset the password in case the user forgot the password. See more on “ Reset password” | Hyperlink |
| | Email \*/Email | Users email address. A password reset link can be sent to this address if the system is configured to do so. User can use this email to log in in the system instead. The email must be unique value | X(100) |
| | Default Language\* /Ngôn ngữ mặc định | Determines the language in which the screen labels are displayed. | Drop-down Select one |
| **Access Detail** | | | |
| | Access Day \*/Ngày truy cập | Seven checkboxes, each of which indicates the day of week on which the user has (checked) or has no (unchecked) access to the system. | Check box Allow to check more than one value |
| | Access time \*/Thời gian truy cập | On days when user has access, the Access Time is the time on and after which user has access to the system i.e. is able to log in to the system | Time |
| | User Profile Effective From Date \*/Tài khoản có hiệu lực từ ngày | Date on and after which this User Profile is effective and the user can log in to the system | Date |
| | User Profile Effective End Date\*/Tài khoản hết hạn sau ngày | Date on and before which this User Profile is effective and the user can log in to the system After this day user can no longer log in to the system | Date |
| | User Group\*/Nhóm người dùng | A drop-down listing the available User groups. The selected group determines the functions to which the user that this user profile is defined for has access. | Drop-down Select one |
| | Report Access Right/ Quyền truy cập báo cáo | Drop-down listing the Report Access Rights groups. The selected Report Access Rights group determines which report(s) the user has access to. | Drop-down Select one |
| | User Status\*/Trạng thái người dùng | Drop-down to select following user status: Active Blocked If account is blocked then user can no longer login into the system. | Drop-down Select one |
| **Reset Password** A pop-up will be appeared when user click to Reset password | | | |
| | New Password\*/ Mật khẩu mới | Enter new password Password must be strong enough. | X(50) |
| | Re-enter Password\*/Nhập lại mật khẩu | Enters their new password again to confirm | X(50) |
| | Save /Lưu | Click to accept the change | Button |
| | Cancel /Hủy | Click to cancel the change | Button |
| **User Permission / Quyền người dùng** **Display for any active User Profile records** **The list contains all permission which applicable for the chosen user** | | | |
| | “Top level module name” E.g: Customer Management | The name of top-level module. | Display |
| | “Second level Module name” E.g: Card | The name of the seconde level selected module. | Display |
| | “Second level Module name” E.g: Card | Click on the second level module to bring up the popup show the access rights fields of chosen module. | Hyperlink |
| | View /Xem | Checked if allow Unchecked if disallow N/A if not applicable this action to that module | Display |
| | Create/Thêm mới | Display |
| | Edit /Sửa | Display |
| | Delete/Xóa | Display |
| | Copy /Sao chép | Display |
| | Approve /Phê duyệt | Display |
| | History/Xem lịch sử | Display |
| | Template/Tạo biểu mẫu | Display |
### Post-Conditions
When create new record then the new user account is successfully created in the system.
The new user receives an email notification with login instructions and temporary password.
When password is resetted then an email notification will send into users email with new password to user can login into the system again.
### Exception Flow