Show login state, active sign-in, and allowed memberships separately.
USER-WP-0036 keeps the token tenant off the membership list and leaves workload decisions unchecked until the catalogue reports them. Assistant: grok Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
parent
1c7634c7ce
commit
85423e8e09
7 changed files with 320 additions and 53 deletions
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Show allowed and active access on the account page"
|
||||
domain: communication
|
||||
repo: user-engine
|
||||
status: ready
|
||||
status: finished
|
||||
flavor: extension
|
||||
owner: grok
|
||||
topic_slug: user-engine
|
||||
|
|
@ -41,7 +41,7 @@ and USER-WP-0028-T02. This plan does not infer those decisions.
|
|||
|
||||
```task
|
||||
id: USER-WP-0036-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "ffc8f42f-5ca3-56a2-8850-d2da9beba72c"
|
||||
```
|
||||
|
|
@ -76,11 +76,16 @@ The observed case renders as: signed in, one active tenant taken from the
|
|||
token, no allowed tenants, no allowed workloads, workload decisions not
|
||||
checked. Keep the layout readable on a phone.
|
||||
|
||||
2026-09-26: the home page and `/onboarding` now render Login state, Active now,
|
||||
and Allowed tenants / Allowed workloads as separate sections. A tenant account
|
||||
is not listed as a membership. Recorded workload rows stay labelled as records,
|
||||
followed by "Workload decisions are not checked."
|
||||
|
||||
## Change the active tenant only through sign-in
|
||||
|
||||
```task
|
||||
id: USER-WP-0036-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "136a27ff-fd3e-5f0a-8a3a-bb080f1965d5"
|
||||
```
|
||||
|
|
@ -100,11 +105,18 @@ one is already recorded.
|
|||
Switching tenant does not claim to end application sessions. The existing
|
||||
sign-out copy remains the place that explains a remaining shared sign-in.
|
||||
|
||||
2026-09-26: an inactive tenant membership links to `/login?tenant_hint=`. The
|
||||
page has no control that marks a second tenant active inside the portal
|
||||
session. Extra active tenants are taken from the verified `active_tenants`
|
||||
claim, and only for `tenant-admin`, `platform-operator`, `platform-root`, or a
|
||||
recorded `vendor` or `multi-hire` membership. An ordinary sign-in shows the
|
||||
token tenant alone.
|
||||
|
||||
## Record the journey and prove the three situations
|
||||
|
||||
```task
|
||||
id: USER-WP-0036-T03
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "4c9b0600-5034-58ce-9b02-90a040f6f65f"
|
||||
```
|
||||
|
|
@ -121,3 +133,10 @@ catalogue decision renders as not checked.
|
|||
|
||||
Do not close USER-WP-0026-T03 or USER-WP-0028-T02 from this plan. They remain
|
||||
the owners of allow, deny, and unavailable workload decisions.
|
||||
|
||||
2026-09-26: U01, U09 and U10 in `docs/account-journeys.md` match the page.
|
||||
`tests/test_account_awareness.py` covers the signed-out home, a token tenant
|
||||
with a tenant account and no membership, an inactive allowed tenant, a
|
||||
recorded workload, an ordinary sign-in that ignores a second tenant claim, and
|
||||
exception roles whose verified token lists two active tenants. 247 unit tests
|
||||
passed. The live portal still serves the previous image.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue