Operator ran into an extended, opaque troubleshooting session in
informed-decision: the decision overview uses a 12h MFA-freshness
window while opening a memo to review/approve uses a strict 900s
window, so the overview kept working while every review page silently
refused, with no session-status visibility and no logout affordance
in that app's UI to diagnose or recover from it.
Requests a reusable account/session-status component (identity,
assurance freshness, logout) that informed-decision, vergabe-teilnahme
and other consumer UIs can mount, built against user-engine's
identity/assurance model. Notes USER-WP-0036 as directly reusable
prior art, and flags -- as a remark, not a decision -- that the actual
component likely belongs in a distinct small repository rather than in
headless user-engine itself or vendored per consumer, to avoid
coupling every consumer's frontend build to user-engine's release
cycle.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
Adopt security-layer-model v0.7 in INTENT.md in this repository's own
voice, restate SCOPE.md from that declaration, and record the
scope-versus-implementation assessment. USER-IN-0001 is answered;
runtime follow-through is USER-WP-0024.
Assistant: grok
Assistant-Session: 01a04cea-f0d6-7ab3-9ffd-881eb6bea6cb