diff --git a/src/user_engine/authentication_policy.py b/src/user_engine/authentication_policy.py index 1f2318e..6138fd6 100644 --- a/src/user_engine/authentication_policy.py +++ b/src/user_engine/authentication_policy.py @@ -53,4 +53,4 @@ def page(csrf, result=None): for receipt in reversed(history): html += '
  • '+escape(str(receipt.get('reference','')))+' — '+escape(str(receipt.get('client','')))+': '+escape(LABELS.get(receipt.get('before'),'Unknown'))+' → '+escape(LABELS.get(receipt.get('after'),'Unknown'))+'; actor '+escape(str(receipt.get('actor','')))+', revision '+escape(str(receipt.get('revision','')))+'.
  • ' html += '' - return html+'

    Check current policy · Return to platform administration

    ' + return html+'

    Check current policy · Return to tenant administration

    ' diff --git a/src/user_engine/factor_recovery.py b/src/user_engine/factor_recovery.py index f859da5..8d5a49c 100644 --- a/src/user_engine/factor_recovery.py +++ b/src/user_engine/factor_recovery.py @@ -92,7 +92,7 @@ def page(csrf, result=None, submitted=None, management_url=''): html+=apply_form(common,submitted['confirmation'],'Retry this recovery') html+='
    '+common+hidden('action','preview')+'
    ' html+='
    '+common+'
    ' - html+='

    Cancel and return to platform administration · Investigate support activity

    ' + html+='

    Cancel and return to tenant administration · Investigate support activity

    ' return html diff --git a/src/user_engine/web.py b/src/user_engine/web.py index 59765bc..a0ad6e2 100644 --- a/src/user_engine/web.py +++ b/src/user_engine/web.py @@ -1327,7 +1327,7 @@ class PortalApplication:

    Showing {min(count, 100)} of {count} matching records, newest first. Filters apply before the 100-record display limit.

    {rows or empty}
    TimeKindTenantActionActorSupport referenceKnown resultNext step

    Audit records describe recorded actions. Delivery acceptance does not prove receipt, and neither proves a provider change or rollback. Check the relevant provider before closing an incident.

    -

    Service recovery · Platform administration

    """) +

    Service recovery · Tenant administration

    """) def _operations_page(self, actor: Any, csrf: str, event_id: str, correlation_id: str) -> str: self.service.tenant_diagnostics(actor, tenant=PLATFORM_TENANT, correlation_id=correlation_id) @@ -1351,7 +1351,7 @@ class PortalApplication: '
    ' '' + (rows or '') - + '
    DeliveryTenantKindStatusSupport referenceRecovery
    No delivery records. This does not prove mail was received.

    Queueing a retry does not send it. Use Review delivery attempt to submit one selected record, then check its result. No background worker is enabled here.

    Return to platform administration

    ') + + '

    Queueing a retry does not send it. Use Review delivery attempt to submit one selected record, then check its result. No background worker is enabled here.

    Return to tenant administration

    ') def _operation_capabilities(self) -> str: capabilities = ( @@ -2140,8 +2140,8 @@ Use the login name they provide; it may differ from your display name.

    No tenants with user memberships are recorded yet.' message = f'

    {escape(error)}

    ' if error else "" return self._page_html( - "Platform administration", - f"""

    Platform administration

    + "Tenant administration", + f"""

    Tenant administration

    Authentication policy

    Manage an existing tenant

    {message} @@ -2196,7 +2196,7 @@ Use the login name they provide; it may differ from your display name.

    Reason

    Retirement is reversible and preserves grant and plan history; there is no hard delete.

    -

    Return to platform administration

    """, +

    Return to tenant administration

    """, ) def _platform_result(self, result: Any, tenant: str, admin_prepared: bool) -> str: @@ -2206,7 +2206,7 @@ Use the login name they provide; it may differ from your display name.

    {escape(tenant)} was processed by the tenant authority.

    {'The first administrator is prepared and awaiting onboarding.' if admin_prepared else 'No first administrator was requested.'}

    Open tenant administration

    -

    Return to platform administration

    """, +

    Return to tenant administration

    """, ) def _onboarding( @@ -2316,7 +2316,7 @@ Use the login name they provide; it may differ from your display name.

    No tenant memberships are recorded. You have no personal tenant memberships. " - "Your platform operator role lets you manage tenants through platform administration." + "Your platform operator role lets you manage tenants through tenant administration." ) else: body = "
  • No tenant memberships are recorded.
  • " @@ -2465,7 +2465,7 @@ Use the login name they provide; it may differ from your display name.

    Manage users' session_id = cookie_value(str(environ.get("HTTP_COOKIE", "")), "ue_session") diff --git a/tests/test_portal_navigation.py b/tests/test_portal_navigation.py index 068f2bb..34abe01 100644 --- a/tests/test_portal_navigation.py +++ b/tests/test_portal_navigation.py @@ -43,6 +43,10 @@ class PortalNavigationTests(unittest.TestCase): _, body = self.get('/onboarding') self.assertIn(b'no personal tenant memberships', body) self.assertIn(b'platform operator role', body) + self.assertIn(b'through tenant administration', body) + _, home = self.get('/') + self.assertIn(b'href="/platform">Tenant administration', home) + self.assertNotIn(b'Platform administration', home) self.assertFalse(self.app.service.store.memberships_for_tenant('tenant:trial:demo-company')) def test_existing_tenant_user_navigation_preserves_authority(self): diff --git a/tests/test_web.py b/tests/test_web.py index afb1f39..7e07b21 100644 --- a/tests/test_web.py +++ b/tests/test_web.py @@ -902,6 +902,8 @@ class PortalApplicationTests(unittest.TestCase): self.app, "/platform", cookie="ue_session=platform" ) self.assertIn(b"Manage an existing tenant", html) + self.assertIn(b"

    Tenant administration

    ", html) + self.assertNotIn(b"Platform administration", html) def test_platform_tenant_authority_denial_is_redacted_and_creates_no_admin(self): oidc = OIDCClient(