@if (auth()->user()->roles()->exists() || auth()->user()->permissions()->exists())
{{--
One navigation, for everyone who has a role.
A Wi-Fi seller used to get a separate cut-down "Reseller Panel"
holding a dashboard, customers and a wallet — which made no sense
for someone who brings their own MikroTik and runs their own
hotspot off it. They need the routers, the hotspot manager, the
portal designer and the rest exactly as the platform owner does.
What each audience may see is decided per page and per host now,
not by handing them a different menu.
--}}
{{--
Admin navigation.
Grouped the way an ISP thinks about its own business — who the
subscribers are, what the network is doing, where the money is —
rather than by which subsystem a page happens to belong to.
Anything that does not fit those groups lives under "Extra" at the
bottom instead of being forced into one.
--}}
@php
// Opens a group when the page you are on lives inside it.
$isOn = fn (array $routes) => collect($routes)->contains(fn ($r) => request()->routeIs($r));
$deviceRoutes = ['mikrotik-sync', 'mikrotik-link', 'mikrotik-hotspot-manager', 'portal-designer', 'equipment'];
$routerSetupRoutes = ['mikrotik-ip-setup', 'mikrotik-pppoe-setup', 'mikrotik-radius-setup',
'mikrotik-firewall-setup', 'mikrotik-walled-garden', 'mikrotik-queue-setup',
'mikrotik-vpn-setup', 'mikrotik-interface-setup', 'mikrotik-backup-setup'];
$billingRoutes = ['reseller.subscription', 'reseller.plan', 'reseller.payment-settings',
'payment-ledger', 'payment-collection', 'payment-invoice', 'collection-edit', 'admin.expenses',
'admin.purchase-requests'];
$commsRoutes = ['sms-setup', 'sms-gateway', 'sms-notifications', 'whatsapp', 'campaigns', 'promo-banners'];
$analyticsRoutes = ['admin.profit-summary', 'collection-report.index', 'customer-summary', 'dis-report'];
$accessRoutes = ['admin-users', 'admin-roles', 'admin-tenants'];
$logRoutes = ['admin.activity-logs', 'admin.login-logs', 'admin.system-logs', 'mikrotik-log-viewer'];
// The platform owner oversees sellers; they do not run a network of
// their own. Anything that configures hardware is a seller's job and
// is hidden from them, so the console stays about the business.
$isPlatformOwner = auth()->user()?->hasRole('Super Admin') ?? false;
// Cheap counts for the at-a-glance badges. Both models scope
// themselves to the signed-in seller, so the owner sees the totals
// across every tenant and a seller sees only their own.
$subscriberCount = \App\Models\CustomersInfo::count();
$routerCount = \App\Models\RouterList::count();
// How many devices are online right now.
//
// Read from the accounting table the minute poller writes, not from
// the routers: the Live sessions page queries every router over the
// tunnel, and doing that on every page render would put a router
// round-trip in front of the whole admin. The trade is that this
// badge can be up to a minute stale, which is the right trade for a
// number in a sidebar. `ended_at` is null while a session is up.
$liveCount = \App\Models\HotspotAccounting::whereNull('ended_at')
->where('last_seen_at', '>=', now()->subMinutes(3))
->count();
@endphp
{{-- ── Overview ───────────────────────────────────────────── --}}
-
{{ __('Overview') }}
{{-- ── Platform ───────────────────────────────────────────
The owner's own work: the sellers on the platform.
Everything below this — subscribers, routers, plans, takings —
belongs to a seller's business, not to whoever runs Bilipoa.
The owner was being shown the whole of it, scoped to "every
tenant at once", which is a view of nobody's network in
particular: a Subscribers page listing four sellers' customers
together answers no question either of them would ask. Worse,
it invited the owner to operate hardware on a tenant's behalf
from a console that cannot tell which tenant they mean.
Working *as* a seller is now explicit — see Sign in as on the
Wi-Fi sellers page — which is both clearer and auditable.
--}}
@if ($isPlatformOwner)
-
{{ __('Wi-Fi sellers') }}
{{ __('Tenant accounts') }}
{{ __('Leads') }}
@endif
{{-- Everything from here to the platform section below is a
seller's own business, and is hidden from the owner. --}}
@unless ($isPlatformOwner)
{{-- ── Customers ──────────────────────────────────────────── --}}
-
{{-- Flat, not a dropdown. Subscribers is the page this section
is named after, so it should open on one click rather than
make you expand a group to reach the only thing in it. --}}
{{ __('Subscribers') }}
@if ($subscriberCount)
{{ $subscriberCount }}
@endif
{{ __('Leads') }}
{{ __('Tickets') }}
{{-- ── Network ────────────────────────────────────────────── --}}
-
{{ __('Live sessions') }}
{{-- Green rather than the subscriber blue: this one is a
live reading, not a total. --}}
@if ($liveCount)
{{ $liveCount }}
@endif
{{ __('Plans') }}
{{ __('Devices') }}
{{ __('Fiber map') }}
{{ __('TR-069') }}
{{ __('Router setup') }}
{{-- ── Finance ────────────────────────────────────────────── --}}
-
{{ __('Billing') }}
{{ __('Vouchers') }}
{{ __('Voucher batches') }}
{{ __('Voucher agents') }}
{{ __('Agent sales') }}
{{-- The platform's own list of the sellers on it. A seller has
no business seeing who else is on the platform. --}}
@if ($isPlatformOwner)
{{ __('Tenants') }}
@endif
{{-- ── Outreach ───────────────────────────────────────────── --}}
-
{{ __('Communications') }}
{{-- ── Insights ───────────────────────────────────────────── --}}
-
{{ __('Analytics') }}
@endunless
{{-- ── Extra ─────────────────────────────────────────────────
Platform administration, and nothing else.
Every entry here configures Bilipoa itself rather than a
seller's business — the public marketing site, the shared
address book, the accounts and roles that span all tenants,
and the audit trail across them. The whole group is hidden
from a seller rather than trimmed item by item: a section
that renders with one link left in it reads as though
something is missing.
--}}
@if ($isPlatformOwner)
Configuration, access control and audit trails.
Most of this belongs to whoever runs the platform rather than
to a seller: the public marketing site, the shared address
book, the accounts and roles that span every tenant, and the
audit trail of all of them. A seller was being shown links
that would only 403 on arrival, since the Tenant role does not
carry those permissions — worse than not offering them.
What a seller keeps is what is genuinely theirs: importing
their own subscribers, and the logs from their own router.
--}}
-
@if ($isPlatformOwner)
{{ __('Site settings') }}
{{ __('Address setup') }}
{{ __('Customer reviews') }}
@endif
{{ __('Import data') }}
@if ($isPlatformOwner)
{{ __('Users & access') }}
@endif
{{ __('Logs & audits') }}
@endif
@else
@endif