Parent: Admin Overview · Related: User Roles & Permissions
Manage all platform users — invite new users, edit their roles and granular permissions, lock accounts, delete users, and sync Firebase Auth state.
/features/admin/users [USER_MANAGEMENT permission]
src/app/features/admin/users/
users.component.ts/html/scss ← main user list
user-permissions.ts ← USER_PERMISSION_GROUPS (permission categories for the dialogs)
user-dialog/ ← edit role + permissions
user-invite-dialog/ ← invite new user
Displays a searchable, paginated ll-table (LlTableImports) of all users in the platform.
Injected services: HlmDialogService, ChangeDetectorRef, NotificationService, UserService, Injector
Key behaviour:
loadData()— fetches all users viaUserServiceonFilterChange(value: FilterToolbarValue)— updates the table filter from theLlFilterToolbarImportstoolbar; the actual predicate is built once inngOnInit()viaFilterPredicateUtils.create(), searching across email/display name and filtering by active/inactiveinviteDialog()— opensUserInviteDialogComponentopenEditDialog(user)— opensUserDialogComponentto edit role/permissions/lockopenDeleteDialog(user)— opensConfirmationDialogComponent, then deletessync()— triggers a Firebase Auth sync to refresh stale user data
Creates a new Firebase Auth user with initial role and permissions.
Form fields: email, password, displayName, role (admin | custom; admin offered to admins only), permissions[], lock
Edits an existing user's role, granular permissions, and lock status.
Form fields: role, permissions[], lock
Both dialogs render permissions[] as grouped checkboxes rather than a plain multiselect: permissions are organized into categories via USER_PERMISSION_GROUPS (user-permissions.ts), with isPermissionSelected() / togglePermission() toggling individual entries into the underlying permissions form control (in both user-dialog.component.ts and user-invite-dialog.component.ts).
Limits for non-admin user managers. The users list shows the actions menu only for users the signed-in user may manage (canManage()). Otherwise the actions button is disabled, with the tooltip "Only an admin can manage this user." For non-admin callers, both dialogs hide the Admin role and disable permissions the caller doesn't hold (canGrantAdmin, canGrantPermission()). All three use the helpers in user-management.ts, which mirror firestore.rules and the user.invite check. See Who Can Manage Users.
See User Roles & Permissions for the full
UserPermissionenum and how claims work.
| Service | Purpose |
|---|---|
UserService |
List, update, delete via Firestore directly; invite() and sync() call the user-invite / user-sync Firebase Functions |
NotificationService |
Toast feedback |