diff --git a/src/user_engine/web.py b/src/user_engine/web.py index fa9008d..c1de182 100644 --- a/src/user_engine/web.py +++ b/src/user_engine/web.py @@ -2071,10 +2071,18 @@ Use the login name they provide; it may differ from your display name.
str: actions = "" if invitation.status.value == "pending": - actions = f""" -""" + invite_root = f"/admin/{escape(tenant)}/invitations/{escape(invitation.invitation_id)}" + hidden = f'' + actions = ( + f'' + f'Sends this invitation again.
Stops this invitation. The person can no longer accept it.
{escape(help_text)}
Login name: {escape(self._directory_login(directory.subject))}
' 'Pass this name on with the sign-in address. It is not the email address, ' 'and signing in by email does not work.
' @@ -2102,13 +2117,23 @@ Use the login name they provide; it may differ from your display name.Password and authenticator status are not available here.') if directory else 'Login not created. Prepare a login before asking this person to sign in.
' actions = "" if not inactive: - actions += form("provision", "Create password setup link" if directory else "Create login") - actions += form("status", "Reactivate" if inactive else "Suspend", status="active" if inactive else "suspended") + if directory: + actions += form("provision", "Create password setup link", "Makes a new single-use link so this person can set a password for the existing login. It does not change the login name.") + else: + actions += form("provision", "Create login", "Creates the directory login. The login name comes from the email name. It is not the display name, and this page cannot rename it afterwards.") + if inactive: + actions += form("status", "Reactivate", "Lets this person use this tenant again. It does not change the login name or the password.", status="active") + else: + actions += form("status", "Suspend access", "Stops this person using this tenant. The login and any other tenant stay as they are.", status="suspended") if status != AccountStatus.DISABLED: - actions += form("remove", "Remove account") + actions += form("remove", "Remove account", "Disables this person's account for this tenant. The shared login is kept.") next_role = "user" if membership.kind == "tenant-admin" else "tenant-admin" - actions += form("role", "Make user" if next_role == "user" else "Make tenant administrator", role=next_role) - if platform_operator: actions += form("recover", "Restore tenant account") + if next_role == "user": + actions += form("role", "Change role", "This person administers the tenant. This changes them to an ordinary user of this tenant. It does not change the login name.", role=next_role) + else: + actions += form("role", "Make tenant administrator", "This person is an ordinary user. This lets them manage the users of this tenant.", role=next_role) + if platform_operator: + actions += form("recover", "Restore tenant account", "Turns this tenant account back on. It creates a directory login only when one is missing. It does not reset a password, remove an authenticator, or change the login name.") return (f'