Repository navigation
Drafts
julietaMendez edited this page May 9, 2022
·
1 revision
For Requirements and Tests, the following will be split into sections according to their micro service.
If required, each section will be further divided up into classes
- Business Account Creation
- Business Account created with an Admin Account
- Admin Account Creation
- Must be created with a valid Business ID
- Created by Another Admin
- Reflect account creation in Business Account Data
- Employee Account Creation
- Must be created with valid Business ID
- Created by an Admin account
- Reflect account creation in Business Account Data
- Save Report Format information
- Save with business account info
- Only done from an admin account
- Account Deletion
- Drop account info from database
- Modify Business account info to reflect this
- Only done from an admin account
- Account Info retrieval
- Retrieve Email, Hashed Password, First Name, Last Name, Business ID
- Login
- Logout
- Set Permissions
- Only done by an admin
- Permissions only apply to Employee Accounts
- Retrieve Permissions
- Used for authorizations
- Edit Account Info
- Email, First name, Last name, password
- Business ID CANNOT be changed
- Worker Account Creation
- Each Password must be hashed, will be using BCrypts hashing algo with 10 rounds
*Business Account Creation - Business Accounts cannot be created without also creating an admin account
- Conversely, an Admin account cannot be created with out a business id
- To deal with this, there will be a special registration function that will override this for Admin account creation
- Each Password must be hashed, will be using BCrypts hashing algo with 10 rounds
- Permissions
- Permissions can only be set or changed by an admin account, to ensure this, the admin account that is changing the permissions will be passed as a parameter along with the set of permissions to save to the Employee account receiving the changes
- Admins by default have no 'permissions' associated with their account and are allowed full access
- Login/Logout
- Password validation will be done on accounts, then grab an authentication token from the Auth microservice.
- Log out on token validation fail
- Report Format updating
- Type of account requesting change will be checked, and must be an AdminAccount.
- Report formats saved with Business account, and can only be changed by a valid AdminAccount
- Account Deletion/Promotion
- These processes require an AdminAccount to be the requester. This will fail if its EmployeeAccount.
- These actions must update the related BusinessAccount data as well.
- All Requests will require a valid Auth token, even for admin accounts.