Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks. Co-authored-by: Cursor <cursoragent@cursor.com>
2.8 KiB
2.8 KiB
Entity: Session user
Authenticated user context for B2B portal — demo mock now, JWT/session later.
Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B
Fields
| Field | Type | Required | Notes |
|---|---|---|---|
id |
string |
✓ | usr_* |
email |
string |
✓ | |
full_name |
string |
✓ | |
phone |
Phone |
||
org_id |
string |
✓ | Active tenant |
member_id |
string |
Link to Member row if enrolled | |
customer_id |
string |
Shared Gishen customer (Ecom/Mob) | |
roles |
PortalRole[] |
✓ | One or more |
locale |
Locale |
✓ | en | am |
avatar_url |
string |
||
org_status |
OrgStatus |
✓ | Denormalized for gating |
permissions |
string[] |
Computed from roles | |
demo_profile |
DemoProfile |
Mock only |
PortalRole
SUPER_USER | HR_ADMIN | FINANCE | MEMBER
DemoProfile (mock /login only)
| Field | Type |
|---|---|
label |
string |
description |
string |
Pre-seeded demo profiles per role against a shared mock org.
Computed permissions
| Permission | Roles |
|---|---|
org:read |
SUPER_USER, HR_ADMIN, FINANCE |
org:write_hr |
SUPER_USER, HR_ADMIN |
members:write |
SUPER_USER, HR_ADMIN |
packages:write |
SUPER_USER, HR_ADMIN |
migration:write |
SUPER_USER, HR_ADMIN |
finance:read |
SUPER_USER, HR_ADMIN, FINANCE |
finance:approve |
SUPER_USER, FINANCE |
clinical:read |
SUPER_USER, MEMBER (own) |
prescriptions:write |
MEMBER (own), SUPER_USER |
Locale preference
locale is persisted on the user record and returned in session. Updated via PATCH /v1/auth/me/locale. Synced to client cookie/localStorage for next-intl.
Clinical withhold
Session drives RBAC. If roles includes HR_ADMIN or FINANCE and not SUPER_USER, all prescription and clinical serializers apply withhold filters automatically.
Sample session (mock demo — HR)
{
"id": "usr_01HHR",
"email": "hr.demo@acme.et",
"full_name": "Demo HR Admin",
"phone": "+251900000001",
"org_id": "org_01DEMO",
"member_id": null,
"customer_id": null,
"roles": ["HR_ADMIN"],
"locale": "en",
"org_status": "active",
"permissions": ["org:read", "org:write_hr", "members:write", "packages:write", "migration:write", "finance:read"],
"demo_profile": {
"label": "HR Administrator",
"description": "Manage members, departments, and packages"
}
}
Sample session (SUPER_USER)
{
"id": "usr_01HSUPER",
"roles": ["SUPER_USER"],
"locale": "am",
"permissions": ["*"],
"demo_profile": {
"label": "Super User",
"description": "Full portal access including clinical detail"
}
}