Access Control and Roles
Permission matrix for Admin, Teacher, and Student roles.
Access Control and Roles
The system enforces three strict roles: administrador, maestro, and alumno.
Permission Matrix
| Module | Administrator | Teacher | Student |
|---|---|---|---|
| Users | Full CRUD | No Access | No Access |
| Groups / Grades | Full CRUD | Assigned groups only | Enrolled groups only |
| Students (Profile) | Full CRUD | Manage students in their groups | Own profile only |
| Student Attendance | Full CRUD | Take attendance in their groups | Personal record lookup |
| Teacher Attendance | Full CRUD | No Access | No Access |
| Tasks / Reports | Full CRUD | Manage in their groups | General inquiry |
Middleware Guards
verifyUser: Validates active session and populatesuserIdandrole.adminOnly: Restricts route exclusively toadministrador.staffOnly: Allows access toadministradorormaestro.
🔒 Controller-Level Scope Check: Even if a route uses
staffOnly, controllers verify that the requesting teacher owns the submittedgradoId.