This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/backend/entities/session-user.md
kirukib 3778801ef5 Ship Gishen B2B institutional portal with polished layout and mock-backed flows.
Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 21:18:23 +03:00

102 lines
2.8 KiB
Markdown

# Entity: Session user
Authenticated user context for B2B portal — demo mock now, JWT/session later.
**Workspace:** `/Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B`
## Fields
| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `id` | `string` | ✓ | `usr_*` |
| `email` | `string` | ✓ | |
| `full_name` | `string` | ✓ | |
| `phone` | `Phone` | | |
| `org_id` | `string` | ✓ | Active tenant |
| `member_id` | `string` | | Link to Member row if enrolled |
| `customer_id` | `string` | | Shared Gishen customer (Ecom/Mob) |
| `roles` | `PortalRole[]` | ✓ | One or more |
| `locale` | `Locale` | ✓ | `en` \| `am` |
| `avatar_url` | `string` | | |
| `org_status` | `OrgStatus` | ✓ | Denormalized for gating |
| `permissions` | `string[]` | | Computed from roles |
| `demo_profile` | `DemoProfile` | | Mock only |
### PortalRole
```
SUPER_USER | HR_ADMIN | FINANCE | MEMBER
```
### DemoProfile (mock `/login` only)
| Field | Type |
|-------|------|
| `label` | `string` |
| `description` | `string` |
Pre-seeded demo profiles per role against a shared mock org.
## Computed permissions
| Permission | Roles |
|------------|-------|
| `org:read` | SUPER_USER, HR_ADMIN, FINANCE |
| `org:write_hr` | SUPER_USER, HR_ADMIN |
| `members:write` | SUPER_USER, HR_ADMIN |
| `packages:write` | SUPER_USER, HR_ADMIN |
| `migration:write` | SUPER_USER, HR_ADMIN |
| `finance:read` | SUPER_USER, HR_ADMIN, FINANCE |
| `finance:approve` | SUPER_USER, FINANCE |
| `clinical:read` | SUPER_USER, MEMBER (own) |
| `prescriptions:write` | MEMBER (own), SUPER_USER |
## Locale preference
`locale` is persisted on the user record and returned in session. Updated via `PATCH /v1/auth/me/locale`. Synced to client cookie/localStorage for next-intl.
## Clinical withhold
Session drives RBAC. If `roles` includes HR_ADMIN or FINANCE and **not** SUPER_USER, all prescription and clinical serializers apply withhold filters automatically.
## Sample session (mock demo — HR)
```json
{
"id": "usr_01HHR",
"email": "hr.demo@acme.et",
"full_name": "Demo HR Admin",
"phone": "+251900000001",
"org_id": "org_01DEMO",
"member_id": null,
"customer_id": null,
"roles": ["HR_ADMIN"],
"locale": "en",
"org_status": "active",
"permissions": ["org:read", "org:write_hr", "members:write", "packages:write", "migration:write", "finance:read"],
"demo_profile": {
"label": "HR Administrator",
"description": "Manage members, departments, and packages"
}
}
```
## Sample session (SUPER_USER)
```json
{
"id": "usr_01HSUPER",
"roles": ["SUPER_USER"],
"locale": "am",
"permissions": ["*"],
"demo_profile": {
"label": "Super User",
"description": "Full portal access including clinical detail"
}
}
```
## Related endpoints
- [`../endpoints/auth.md`](../endpoints/auth.md)