Repository navigation
feat!: mirror member roles and per-sign-in sessions in the fake tenant - #84
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Member
Author
|
test: pin role and cascade scoping in the tenant contract — adds a contract step proving a role revoke and a last-membership cascade stay with the person and organization they name, makes the cross-organization check seat the member in the second organization so it can fail, asserts the grant's |
KyleJune
pushed a commit
that referenced
this pull request
Oct 7, 2026
## [0.14.0](0.13.0...0.14.0) (2026-10-07) ### ⚠ BREAKING CHANGES * Login sessions follow the browser, not `signInAs`. Repeated authorization requests after one `signInAs` no longer share a session; each starts its own unless it sends back the session cookie the tenant set, so a test that relied on a second sign-in revoking the first credential must carry that cookie. Conversely, calling `signInAs` again no longer starts a new browser: a browser that carries the cookie continues its session for the same person, so a test modelling two devices needs two cookie jars (browser contexts). Revoking someone's last accepted role in an organization through `DELETE …/members/:userId/:role` now also withdraws their pending memberships and unaccepted invitations there and drops the permissions `addMember` seeded, so a later accept of such an offer answers `invalid` and rejoining restores nothing. `TenantContractFixture` requires a new `addRole(permissions)` hook that defines a tenant-wide role and returns its id. 🤖 Generated with [Claude Code](https://claude.com/claude-code) ### Features * mirror member roles and per-sign-in sessions in the fake tenant ([#84](#84)) ([e94a8d7](e94a8d7))
|
🎉 This PR is included in version 0.14.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
createFakeTenantnow mirrors three behaviours of a Udibo Identity tenant that apps building organization and account screens rely on:GET …/organizations/:organizationId/members/:userId/roles,POST …/members/:userId/roles({ roleId }) andDELETE …/members/:userId/roles/:roleId.member-rolesnow names each tenant-defined role by theidthe grant takes; built-in tiers carry noid. A granted role'spermissionsanswer in/api/checkand introspection inside that organization only. Refusals follow the tenant: a non-manager gets the404an unknown organization gets; a pending member, a non-member and an unknown user share one404; an unknown role is404;400for a grant naming no role;403for revoking a built-in role, which no one in the fake holds as an application role.addMemberseeded, and the offers still open to them (pending memberships, and unaccepted invitations to their address). Rejoining grants only what the new offer names. Revoking one of several accepted roles, or withdrawing a pending offer from someone who is not a member, ends nothing else.HttpOnlycookie on the tenant's origin naming it. A request that sends the cookie back continues that session while it is live and belongs to the personsignInAschose, as the same browser does on a tenant, so a person can have several devices in the account sessions list.Changes
defineOrganizationRoleacceptsidandpermissionsand returns the role's id; redefining a slug keeps its id, and naming a new id for a defined slug throws. A resource grant naming a defined role lists that role's id.removeMemberalso ends the application roles the membership held; deleting an organization forgets its roles.TenantContractFixturegains a requiredaddRole(permissions)hook.llms-full.txtupdated.Testing
deno task check,deno task test --parallel --reporter=dot(239 passed) anddeno task test:allall green.Closes
Nothing; there is no tracking issue in this repository.
BREAKING CHANGE: Login sessions follow the browser, not
signInAs. Repeated authorization requests after onesignInAsno longer share a session; each starts its own unless it sends back the session cookie the tenant set, so a test that relied on a second sign-in revoking the first credential must carry that cookie. Conversely, callingsignInAsagain no longer starts a new browser: a browser that carries the cookie continues its session for the same person, so a test modelling two devices needs two cookie jars (browser contexts). Revoking someone's last accepted role in an organization throughDELETE …/members/:userId/:rolenow also withdraws their pending memberships and unaccepted invitations there and drops the permissionsaddMemberseeded, so a later accept of such an offer answersinvalidand rejoining restores nothing.TenantContractFixturerequires a newaddRole(permissions)hook that defines a tenant-wide role and returns its id.🤖 Generated with Claude Code