diff --git a/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md b/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md new file mode 100644 index 00000000..5d19ce81 --- /dev/null +++ b/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md @@ -0,0 +1,7 @@ +# Local user identity UI + +`AuthGate` already maps local authentication mode to `canLogout=true`. The shell +should render the authenticated identity and its logout control only when +`authenticatedUser` is present and `canLogout` is true. Upstream/Authentik and +OIDC modes therefore hide both elements. Local authentication behavior remains +unchanged. diff --git a/frontend/src/shell/AppShell.auth.test.tsx b/frontend/src/shell/AppShell.auth.test.tsx index 16d5a8df..7617fd66 100644 --- a/frontend/src/shell/AppShell.auth.test.tsx +++ b/frontend/src/shell/AppShell.auth.test.tsx @@ -65,7 +65,7 @@ describe("authenticated shell permissions", () => { expect(screen.getByRole("button", { name: "All sessions" })).toBeInTheDocument(); }); - test("hides logout outside local authentication while preserving the identity", async () => { + test("hides identity and logout outside local authentication", async () => { let logoutCalls = 0; server.use(http.post("/api/auth/logout", () => { logoutCalls += 1; @@ -79,7 +79,7 @@ describe("authenticated shell permissions", () => { permissions: ["session.use"], }, false); - expect(await screen.findByText("portal-user")).toBeInTheDocument(); + await waitFor(() => expect(screen.queryByText("portal-user")).not.toBeInTheDocument()); expect(screen.queryByRole("button", { name: "Log out" })).not.toBeInTheDocument(); expect(logoutCalls).toBe(0); }); diff --git a/frontend/src/shell/AppShell.tsx b/frontend/src/shell/AppShell.tsx index d7097cd8..388ee9e3 100644 --- a/frontend/src/shell/AppShell.tsx +++ b/frontend/src/shell/AppShell.tsx @@ -716,16 +716,14 @@ export function AppShell({ canLogout }: AppShellProps) {
Human In The Loop

- {authenticatedUser && ( + {authenticatedUser && canLogout && (
{authenticatedUser.displayName ?? authenticatedUser.subject} - {canLogout && ( - - )} +
)}