Headless multi-application, multi-tenant user mangement engine.
Find a file
tegwick 8b3b72fcb2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
File USER-IN-0002: reusable account/session-status UI component
Operator ran into an extended, opaque troubleshooting session in
informed-decision: the decision overview uses a 12h MFA-freshness
window while opening a memo to review/approve uses a strict 900s
window, so the overview kept working while every review page silently
refused, with no session-status visibility and no logout affordance
in that app's UI to diagnose or recover from it.

Requests a reusable account/session-status component (identity,
assurance freshness, logout) that informed-decision, vergabe-teilnahme
and other consumer UIs can mount, built against user-engine's
identity/assurance model. Notes USER-WP-0036 as directly reusable
prior art, and flags -- as a remark, not a decision -- that the actual
component likely belongs in a distinct small repository rather than in
headless user-engine itself or vendored per consumer, to avoid
coupling every consumer's frontend build to user-engine's release
cycle.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 21:36:58 +02:00
.claude/rules Hygiene: SCOPE stance sentence, stack/architecture stubs, first-session archive 2026-08-29 14:37:38 +02:00
.forgejo/workflows Run journey CI in a pinned Python environment 2026-09-13 12:22:17 +02:00
docs Close recovery acceptance and reconcile blocked workplans 2026-09-27 17:54:47 +02:00
history Declare Engine/PIP and open USER-WP-0024 for layer conformance 2026-08-29 11:56:06 +02:00
intakes File USER-IN-0002: reusable account/session-status UI component 2026-09-27 21:36:58 +02:00
migrations/postgres feat: add durable store conformance harness 2026-06-16 00:20:29 +02:00
openapi Report tenant grouping from the authority record 2026-08-18 10:56:54 +02:00
registry Draft capability entry (reuse-surface REUSE-WP-0017-T04, cohort 3) 2026-07-06 19:50:54 +02:00
scripts Converge layer checker on GH-DEC-2026-021. 2026-09-22 16:14:32 +02:00
src/user_engine Allow a signed-in person to save their own profile. 2026-09-27 02:18:51 +02:00
tests Close recovery acceptance and reconcile blocked workplans 2026-09-27 17:54:47 +02:00
wiki Adapt USER-WP-0021 and USER-WP-0023 to published policy-nexus contracts 2026-08-19 09:51:08 +02:00
workplans Close recovery acceptance and reconcile blocked workplans 2026-09-27 17:54:47 +02:00
.custodian-brief.md Refresh State Hub brief after loose-end reconciliation 2026-09-27 17:56:06 +02:00
.gitignore Ignore .repo-manager local index 2026-08-29 11:59:20 +02:00
.repo-classification.yaml Add .repo-classification.yaml (CUST-WP-0050 T11 agent first-pass) 2026-06-22 17:47:43 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:22:18 +02:00
CLAUDE.md Hygiene: SCOPE stance sentence, stack/architecture stubs, first-session archive 2026-08-29 14:37:38 +02:00
Containerfile Add KeyCape PKCE browser sessions 2026-07-28 00:06:21 +02:00
INTENT.md Apply GH-DEC-2026-020: de-version the standard path and widen the checker. 2026-09-21 09:36:59 +02:00
layer.yaml Show an existing NetKingdom sign-in before the account site continues it. 2026-09-27 00:21:34 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 01:12:41 +02:00
Makefile Implement role-based account journeys with database and browser acceptance suites 2026-09-13 12:20:02 +02:00
pep-stance.yaml Implement USER-WP-0024 security layer conformance 2026-08-29 12:53:16 +02:00
pyproject.toml Add KeyCape PKCE browser sessions 2026-07-28 00:06:21 +02:00
README.md test: add registration security conformance 2026-06-15 23:59:45 +02:00
SCOPE.md Hygiene: SCOPE stance sentence, stack/architecture stubs, first-session archive 2026-08-29 14:37:38 +02:00
uv.lock Synchronize session work records and dependency lock 2026-09-14 00:16:32 +02:00
WORK-RECORDS.md Close recovery acceptance and reconcile blocked workplans 2026-09-27 17:54:47 +02:00

Headless multi-application, multi-tenant user management engine.

Development

make test

See docs/development.md, docs/configuration.md, docs/contracts.md, docs/canon-mapping.md, docs/canon-interface-card.yaml, docs/evidence-gap-examples.md, docs/family-dataspace-onboarding.md, docs/netkingdom-registration-onboarding-vision.md, docs/postgres-durable-store-consumer-requirements.md, docs/examples.md, docs/registration-identity-and-factor-model.md, docs/prepared-accounts-and-entitlement-claims.md, docs/hats-realms-services-assets-access-profiles.md, docs/onboarding-journeys-and-welcome-protocols.md, docs/registration-and-access-management-ui.md, docs/scenarios.md, docs/registration-scenario-and-security-conformance.md, docs/operability.md, docs/release.md, docs/ui-contracts.md, docs/identity-domain-naming-decision.md, and docs/final-assessment.md for implementation boundaries, contracts, canon mappings, examples, and release readiness.