This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/features/auth-roles.md
kirukib f2e992e0bd Add multi-method login UI and document auth method contracts.
Surface Google, email, phone, and Telegram on login (mocked), polish the brand panel and fixes for Button/Menu, and keep the backend spec sheet aligned.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-07 16:12:43 +03:00

83 lines
2.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Feature: Auth & roles
Demo login with role selector, session management, and role-filtered navigation.
**Workspace:** `/Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B`
## Pages
| Route | Purpose |
|-------|---------|
| `/login` | Sign-in methods (Google, email, phone, Telegram — **mocked**) + demo persona dropdown + locale switcher; register/join CTAs |
| `/profile` | Own account — see [profile.md](profile.md) |
## Roles
| Role | Nav sections |
|------|--------------|
| `SUPER_USER` | All — Organisation, Departments, Migration, Members, Packages, Finance, Settings |
| `HR_ADMIN` | Organisation, Departments, Migration, Members, Packages, Settings |
| `FINANCE` | Finance, Statements (read org summary) |
| `MEMBER` | Me, Orders, Prescriptions |
## Entities
- [`SessionUser`](../backend/entities/session-user.md)
## Endpoints
- [`auth.md`](../backend/endpoints/auth.md)
- `POST /v1/auth/login`
- `POST /v1/auth/logout`
- `GET /v1/auth/me`
- `GET /v1/auth/demo-profiles`
## Demo login UX
1. Optional: **Google / Email / Phone / Telegram** (mock) — toast note, then signs in as the selected demo persona.
2. Or pick a **test user** from the dropdown: Selam Super, Hanna HR, Fikru Finance, Abebe Member.
3. Optional locale toggle (en/am) on the login panel.
4. Continue / method buttons set session via `loginAsUser(id)` and redirect to that user’s home path.
5. Topbar menu: Profile → `/profile`; "Switch demo user" → `/login`.
6. Multi-role demo (`user_super`) can switch active role on `/profile`.
Pre-seeded demo data: single mock org (`org_yaltopia` / Yaltopia) with realistic members, packages, spend.
## Route guards
Middleware or layout checks:
| Check | Behavior |
|-------|----------|
| Unauthenticated | Redirect to `/login` |
| MEMBER on `/finance` | 403 → member home |
| HR on `/prescriptions/:id` clinical | Withhold / redirect |
| Pending org | Block `/members`, `/packages` (active), migration commit |
## Clinical withhold
Enforced at API mock layer and UI:
- HR_ADMIN / FINANCE menus exclude Prescriptions clinical views.
- SUPER_USER sees all nav items including member Rx support paths.
## Validation / errors
| Scenario | Code |
|----------|------|
| Invalid demo role | `VALIDATION_FAILED` |
| Expired session | `UNAUTHENTICATED` |
## Mock implementation notes
```
src/mocks/auth.ts — demo profiles + session
src/lib/api/auth.ts — adapter
src/types/session.ts — SessionUser type
```
## Related
- [i18n.md](i18n.md) — locale on login
- [org-registration.md](org-registration.md) — public CTAs from login