This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/features/auth-roles.md
kirukib 3778801ef5 Ship Gishen B2B institutional portal with polished layout and mock-backed flows.
Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 21:18:23 +03:00

2.2 KiB

Feature: Auth & roles

Demo login with role selector, session management, and role-filtered navigation.

Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B

Pages

Route Purpose
/login Demo role selector + locale switcher; "Register organisation" / "Request registration" CTAs

Roles

Role Nav sections
SUPER_USER All — Organisation, Departments, Migration, Members, Packages, Finance, Settings
HR_ADMIN Organisation, Departments, Migration, Members, Packages, Settings
FINANCE Finance, Statements (read org summary)
MEMBER Me, Orders, Prescriptions

Entities

Endpoints

  • auth.md
    • POST /v1/auth/login
    • POST /v1/auth/logout
    • GET /v1/auth/me
    • GET /v1/auth/demo-profiles

Demo login UX

  1. User selects persona: Super User, HR Administrator, Finance Approver, Member.
  2. Optional locale toggle (en/am).
  3. "Continue as …" sets mock session and redirects to role-appropriate home.
  4. Topbar profile menu includes "Switch demo user" → returns to /login.

Pre-seeded demo data: single mock org (org_01DEMO) with realistic members, packages, spend.

Route guards

Middleware or layout checks:

Check Behavior
Unauthenticated Redirect to /login
MEMBER on /finance 403 → member home
HR on /prescriptions/:id clinical Withhold / redirect
Pending org Block /members, /packages (active), migration commit

Clinical withhold

Enforced at API mock layer and UI:

  • HR_ADMIN / FINANCE menus exclude Prescriptions clinical views.
  • SUPER_USER sees all nav items including member Rx support paths.

Validation / errors

Scenario Code
Invalid demo role VALIDATION_FAILED
Expired session UNAUTHENTICATED

Mock implementation notes

src/mocks/auth.ts       — demo profiles + session
src/lib/api/auth.ts     — adapter
src/types/session.ts    — SessionUser type