# Development Test Users

These accounts exist only for local/development testing while `DEV_LOGIN_ENABLED=true`.
`ProductionConfig` disables development login automatically.

| Persona | Email | Seeded roles | Intended access |
|---|---|---|---|
| Admin | `admin@sevasetu.local` | `SUPER_ADMIN`, `EMPLOYEE` | Admin dashboard plus employee portal; all seeded permissions |
| Manager | `manager@sevasetu.local` | `MANAGER`, `EMPLOYEE` | Employee portal plus manager approval inbox |
| Employee | `employee@sevasetu.local` | `EMPLOYEE` | Employee dashboard, Seva Bhaav, Seva Daan and My Impact |

The employee reports to the seeded manager so manager-approval testing can be connected later.

## Refresh the development users

Run this after pulling/updating the starter code:

```bash
python scripts/seed.py
```

The seed is idempotent: it updates existing role mappings and demo accounts instead of creating duplicates.

## Login

Open:

```text
http://127.0.0.1:5000/auth/login
```

Use one of the three one-click development login buttons. No password and no Piramal SSO are required in development mode.

## Access-control checks

1. Login as Employee and try `/admin/` or `/manager/approvals` -> should return Access denied (403).
2. Login as Manager -> `/manager/approvals` should open, `/admin/` should return 403.
3. Login as Admin -> `/admin/` should open, and the employee portal is also available.

## Production safety

Do not enable `DEV_LOGIN_ENABLED` in production. `ProductionConfig` forces it to `False` even if the environment variable is present.
