fix(frontend): hide server-authenticated user identity

This commit is contained in:
User
2026-08-22 22:20:33 +02:00
parent 3fdc278e7a
commit c476c5551b
3 changed files with 13 additions and 8 deletions
@@ -0,0 +1,7 @@
# Local user identity UI
`AuthGate` already maps local authentication mode to `canLogout=true`. The shell
should render the authenticated identity and its logout control only when
`authenticatedUser` is present and `canLogout` is true. Upstream/Authentik and
OIDC modes therefore hide both elements. Local authentication behavior remains
unchanged.
+2 -2
View File
@@ -65,7 +65,7 @@ describe("authenticated shell permissions", () => {
expect(screen.getByRole("button", { name: "All sessions" })).toBeInTheDocument();
});
test("hides logout outside local authentication while preserving the identity", async () => {
test("hides identity and logout outside local authentication", async () => {
let logoutCalls = 0;
server.use(http.post("/api/auth/logout", () => {
logoutCalls += 1;
@@ -79,7 +79,7 @@ describe("authenticated shell permissions", () => {
permissions: ["session.use"],
}, false);
expect(await screen.findByText("portal-user")).toBeInTheDocument();
await waitFor(() => expect(screen.queryByText("portal-user")).not.toBeInTheDocument());
expect(screen.queryByRole("button", { name: "Log out" })).not.toBeInTheDocument();
expect(logoutCalls).toBe(0);
});
+4 -6
View File
@@ -716,16 +716,14 @@ export function AppShell({ canLogout }: AppShellProps) {
<br />
Human In The Loop
</p>
{authenticatedUser && (
{authenticatedUser && canLogout && (
<div className="mt-4 flex items-center justify-between gap-2 border-t border-border/70 pt-3 text-left">
<span className="min-w-0 truncate text-xs text-muted-foreground" title={authenticatedUser.displayName ?? authenticatedUser.subject}>
{authenticatedUser.displayName ?? authenticatedUser.subject}
</span>
{canLogout && (
<Button variant="ghost" size="xs" onClick={() => { void signOut().catch(() => undefined); }}>
Log out
</Button>
)}
<Button variant="ghost" size="xs" onClick={() => { void signOut().catch(() => undefined); }}>
Log out
</Button>
</div>
)}
</div>