Surface Google, email, phone, and Telegram on login (mocked), polish the brand panel and fixes for Button/Menu, and keep the backend spec sheet aligned. Co-authored-by: Cursor <cursoragent@cursor.com>
2.5 KiB
2.5 KiB
Feature: Auth & roles
Demo login with role selector, session management, and role-filtered navigation.
Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B
Pages
| Route | Purpose |
|---|---|
/login |
Sign-in methods (Google, email, phone, Telegram — mocked) + demo persona dropdown + locale switcher; register/join CTAs |
/profile |
Own account — see profile.md |
Roles
| Role | Nav sections |
|---|---|
SUPER_USER |
All — Organisation, Departments, Migration, Members, Packages, Finance, Settings |
HR_ADMIN |
Organisation, Departments, Migration, Members, Packages, Settings |
FINANCE |
Finance, Statements (read org summary) |
MEMBER |
Me, Orders, Prescriptions |
Entities
Endpoints
auth.mdPOST /v1/auth/loginPOST /v1/auth/logoutGET /v1/auth/meGET /v1/auth/demo-profiles
Demo login UX
- Optional: Google / Email / Phone / Telegram (mock) — toast note, then signs in as the selected demo persona.
- Or pick a test user from the dropdown: Selam Super, Hanna HR, Fikru Finance, Abebe Member.
- Optional locale toggle (en/am) on the login panel.
- Continue / method buttons set session via
loginAsUser(id)and redirect to that user’s home path. - Topbar menu: Profile →
/profile; "Switch demo user" →/login. - Multi-role demo (
user_super) can switch active role on/profile.
Pre-seeded demo data: single mock org (org_yaltopia / Yaltopia) with realistic members, packages, spend.
Route guards
Middleware or layout checks:
| Check | Behavior |
|---|---|
| Unauthenticated | Redirect to /login |
MEMBER on /finance |
403 → member home |
HR on /prescriptions/:id clinical |
Withhold / redirect |
| Pending org | Block /members, /packages (active), migration commit |
Clinical withhold
Enforced at API mock layer and UI:
- HR_ADMIN / FINANCE menus exclude Prescriptions clinical views.
- SUPER_USER sees all nav items including member Rx support paths.
Validation / errors
| Scenario | Code |
|---|---|
| Invalid demo role | VALIDATION_FAILED |
| Expired session | UNAUTHENTICATED |
Mock implementation notes
src/mocks/auth.ts — demo profiles + session
src/lib/api/auth.ts — adapter
src/types/session.ts — SessionUser type
Related
- i18n.md — locale on login
- org-registration.md — public CTAs from login