family link: which accounts belong to a household, and GET /api/admin/family

household_people joins a roster family to the accounts of its parents; a
household can have two, a person can rarely be on two. PUT
/roster/households/{id}/people sets it (admin and above). GET /family
(account:self) returns the signed-in person's own households with scouts
and this year's checklist, and nothing else - the parent view of the
roster, read only. Inactive households drop off it.

tests/smoke_admin.py 141 -> 147.
This commit is contained in:
2026-09-04 19:19:34 -04:00
parent 504538567f
commit 7f04d57665
3 changed files with 89 additions and 0 deletions
+35
View File
@@ -846,9 +846,44 @@ def get_household(request: Request, hid: str, year: str = None, x_admin_token: s
h = store.get_household(hid, _year(year))
if not h:
raise HTTPException(404, "no such household")
h["people"] = store.household_people(hid)
return h
@router.put("/roster/households/{hid}/people")
def put_household_people(request: Request, hid: str, payload: dict = Body(...), x_admin_token: str = Header(None)):
"""Which accounts belong to this family: body {person_ids: [...]}. This is
what a parent's Family page is built from. Admin and above."""
_auth(request, x_admin_token, "people:invite_leader")
if not _person(request):
raise HTTPException(403, "needs a signed-in person")
ids = [str(p) for p in payload.get("person_ids") or []]
known = {p["id"] for p in identity.list_people()}
bad = [p for p in ids if p not in known]
if bad:
raise HTTPException(422, "unknown person ids: %s" % ", ".join(bad))
res = store.set_household_people(hid, ids)
if res is None:
raise HTTPException(404, "no such household")
_log(request, "roster.household_people", "%s -> %d account(s)" % (hid, len(res)))
return {"person_ids": res}
@router.get("/family")
def my_family(request: Request, year: str = None, x_admin_token: str = Header(None)):
"""The signed-in person's own families: scouts, dens, and this year's
checklist as seen from the family's side. account:self, so a parent with
a member account gets exactly their own and nothing else."""
_auth(request, x_admin_token, "account:self")
person = _person(request)
if not person:
raise HTTPException(403, "needs a signed-in person")
y = _year(year)
return {"year": y, "items": list(store.ROSTER_ITEMS), "item_words": store.ROSTER_ITEM_WORDS,
"households": store.households_for_person(person["id"], y),
"me": {"email": person["email"], "name": person.get("preferred_name") or person.get("full_name")}}
@router.post("/roster/households", status_code=201)
def create_household(request: Request, payload: dict = Body(...), x_admin_token: str = Header(None)):
"""A family. Body: parent_name (required), email, phone, second_parent,