Show login state, active sign-in, and allowed memberships separately.
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Has been cancelled
Build and Publish Container Image / build-and-push (push) Successful in 41s
Account journey acceptance / journeys (push) Successful in 9s

USER-WP-0036 keeps the token tenant off the membership list and leaves workload decisions unchecked until the catalogue reports them.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-26 20:46:38 +02:00
parent 1c7634c7ce
commit 85423e8e09
7 changed files with 320 additions and 53 deletions

View file

@ -19,9 +19,10 @@ class AccountRecoveryTests(unittest.TestCase):
self.assertIn(b'/onboarding', body)
self.assertIn(b'This portal is signed in as', body)
_, body = self.get('/onboarding')
self.assertIn(b'Current identity', body)
self.assertIn(b'Workload access', body)
self.assertIn(b'No workload-specific access is recorded', body)
self.assertIn(b'Login state', body)
self.assertIn(b'Allowed workloads', body)
self.assertIn(b'No workload access is recorded.', body)
self.assertIn(b'Workload decisions are not checked.', body)
def test_shared_logout_clears_portal_then_uses_provider_confirmation(self):
response, _ = invoke(self.app, '/logout', method='POST', cookie='ue_session=operator', form={'csrf_token':'wrong','scope':'shared'})