# ADR-0009 — Authentication-only access control (RBAC present but unenforced)

> Produced by the Reversa **Detective** (phase: interpretation) · doc_level: `complete`
> Retroactive ADR reconstructed from `routes/web.php`, `config/admin.php`, and `database/seeds`. See `permissions.md` for the full matrix.

- **Status:** Accepted (as-built) 🟢 · confirmed with the team 2026-09-18, no longer flagged for review
- **Confidence:** 🟢 CONFIRMED (mechanism) / 🟡 (rationale inferred)

## Context

TinyPOS is operated by a single shop. The Encore\Admin package (ADR-0001) ships a full table-driven RBAC model, but the shop's day-to-day need is simply "the operator is logged in".

## Decision

Protect all application routes with only the `admin` **auth** guard (`middleware ['web','admin']`), and do **not** wire the package's per-route permission middleware. Seed a single `administrator` role holding the `*` permission. No Laravel Gates, Policies, or `can:` middleware are added in `app/`.

## Consequences

- 🟢 Any authenticated administrator can do everything — simple and adequate for a single-operator shop.
- 🟡 The RBAC tables are decorative from the app's perspective; they govern only the package's own `/auth/*` screens.
- 🟢 PERM-1: confirmed with the team — the single-operator model (no cashier/owner separation) is intentional, not a gap. Introducing role separation later would still require both seeding roles/permissions **and** wiring the permission middleware — neither exists today.
- 🟢 PERM-2: the seeded default credential `admin`/`admin` — confirmed with the team that production has already rotated this password; residual risk is theoretical (re-seeding a fresh environment), not a live exposure.
