This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/backend/entities/session-user.md
kirukib 3778801ef5 Ship Gishen B2B institutional portal with polished layout and mock-backed flows.
Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 21:18:23 +03:00

2.8 KiB

Entity: Session user

Authenticated user context for B2B portal — demo mock now, JWT/session later.

Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B

Fields

Field Type Required Notes
id string ✓ usr_*
email string ✓
full_name string ✓
phone Phone
org_id string ✓ Active tenant
member_id string Link to Member row if enrolled
customer_id string Shared Gishen customer (Ecom/Mob)
roles PortalRole[] ✓ One or more
locale Locale ✓ en | am
avatar_url string
org_status OrgStatus ✓ Denormalized for gating
permissions string[] Computed from roles
demo_profile DemoProfile Mock only

PortalRole

SUPER_USER | HR_ADMIN | FINANCE | MEMBER

DemoProfile (mock /login only)

Field Type
label string
description string

Pre-seeded demo profiles per role against a shared mock org.

Computed permissions

Permission Roles
org:read SUPER_USER, HR_ADMIN, FINANCE
org:write_hr SUPER_USER, HR_ADMIN
members:write SUPER_USER, HR_ADMIN
packages:write SUPER_USER, HR_ADMIN
migration:write SUPER_USER, HR_ADMIN
finance:read SUPER_USER, HR_ADMIN, FINANCE
finance:approve SUPER_USER, FINANCE
clinical:read SUPER_USER, MEMBER (own)
prescriptions:write MEMBER (own), SUPER_USER

Locale preference

locale is persisted on the user record and returned in session. Updated via PATCH /v1/auth/me/locale. Synced to client cookie/localStorage for next-intl.

Clinical withhold

Session drives RBAC. If roles includes HR_ADMIN or FINANCE and not SUPER_USER, all prescription and clinical serializers apply withhold filters automatically.

Sample session (mock demo — HR)

{
  "id": "usr_01HHR",
  "email": "hr.demo@acme.et",
  "full_name": "Demo HR Admin",
  "phone": "+251900000001",
  "org_id": "org_01DEMO",
  "member_id": null,
  "customer_id": null,
  "roles": ["HR_ADMIN"],
  "locale": "en",
  "org_status": "active",
  "permissions": ["org:read", "org:write_hr", "members:write", "packages:write", "migration:write", "finance:read"],
  "demo_profile": {
    "label": "HR Administrator",
    "description": "Manage members, departments, and packages"
  }
}

Sample session (SUPER_USER)

{
  "id": "usr_01HSUPER",
  "roles": ["SUPER_USER"],
  "locale": "am",
  "permissions": ["*"],
  "demo_profile": {
    "label": "Super User",
    "description": "Full portal access including clinical detail"
  }
}