<?php

namespace App\Console\Commands;

use Illuminate\Console\Command;

class MigrateFinancePermissions extends Command
{
    protected $signature = 'hrms:finance-migrate-permissions
        {--company_id=* : Limit to specific company IDs}
        {--assign_role=employee : Role for users with no role_id}
        {--dry-run : Preview changes without writing}';

    protected $description = 'Apply split finance permissions to existing tenants (seeds + role sync).';

    public function handle(): int
    {
        $this->info('Migrating finance permissions for existing tenants…');
        $this->newLine();

        $exit = $this->call('hrms:reset-permissions', [
            '--company_id' => $this->option('company_id'),
            '--assign_role' => $this->option('assign_role'),
            '--dry-run' => $this->option('dry-run'),
        ]);

        if ($exit !== self::SUCCESS) {
            return $exit;
        }

        $this->newLine();
        $this->line('Finance role split applied:');
        $this->line('  • Staff → finance_self_view + expenses_create_own');
        $this->line('  • Manager → finance_team_view + expenses_approve');
        $this->line('  • HR → finance_operational (no treasury)');
        $this->line('  • Finance → finance_treasury_view + full treasury');
        $this->newLine();
        $this->warn('Review custom roles: HR users with legacy finance_view may still see treasury until you edit those roles.');
        $this->line('Clear caches after deploy: php artisan config:clear && php artisan route:clear');

        return self::SUCCESS;
    }
}
