Allow Followers with POS permission to collect payments for accessible contacts
S
Sebastian Christ
When “Only Assigned Data” is enabled, a user can be given access to a specific contact by adding them as a Follower.
The user can then:
- see and open the contact
- work with the contact
- see and select the contact in POS
- have full permission to use POS and collect payments
However, the user cannot collect a payment for that contact unless they are also the Assigned User. The transaction fails with an HTTP 404 / DioException.
Why this is a problem
A contact can only have one Assigned User, but multiple users can be Followers.
In a multi-user POS environment, several employees or volunteers may need to collect payments for the same contact. Changing the Assigned User every time another user processes a payment is not practical and also changes the actual ownership/responsibility of the contact.
From a permission perspective, the logic should ideally be:
User has access to the contact (Assigned User OR Follower) + User has POS/payment permission = User can collect payment for that contact.
This would still allow businesses and organizations to keep “Only Assigned Data” enabled and prevent users from accessing the entire contact database.
It would simply make explicitly granted Follower access work consistently within POS.
Current:
Assigned User + POS permission → Payment allowed
Follower + POS permission → Payment denied
Suggested:
Assigned User OR Follower + POS permission → Payment allowed
Log In