From c476c5551b506e5ea414a65caf7df9649b69b99b Mon Sep 17 00:00:00 2001
From: User
Date: Sat, 22 Aug 2026 22:20:33 +0200
Subject: [PATCH] fix(frontend): hide server-authenticated user identity
---
.../specs/2026-08-22-local-user-identity-ui-design.md | 7 +++++++
frontend/src/shell/AppShell.auth.test.tsx | 4 ++--
frontend/src/shell/AppShell.tsx | 10 ++++------
3 files changed, 13 insertions(+), 8 deletions(-)
create mode 100644 docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md
diff --git a/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md b/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md
new file mode 100644
index 00000000..5d19ce81
--- /dev/null
+++ b/docs/superpowers/specs/2026-08-22-local-user-identity-ui-design.md
@@ -0,0 +1,7 @@
+# Local user identity UI
+
+`AuthGate` already maps local authentication mode to `canLogout=true`. The shell
+should render the authenticated identity and its logout control only when
+`authenticatedUser` is present and `canLogout` is true. Upstream/Authentik and
+OIDC modes therefore hide both elements. Local authentication behavior remains
+unchanged.
diff --git a/frontend/src/shell/AppShell.auth.test.tsx b/frontend/src/shell/AppShell.auth.test.tsx
index 16d5a8df..7617fd66 100644
--- a/frontend/src/shell/AppShell.auth.test.tsx
+++ b/frontend/src/shell/AppShell.auth.test.tsx
@@ -65,7 +65,7 @@ describe("authenticated shell permissions", () => {
expect(screen.getByRole("button", { name: "All sessions" })).toBeInTheDocument();
});
- test("hides logout outside local authentication while preserving the identity", async () => {
+ test("hides identity and logout outside local authentication", async () => {
let logoutCalls = 0;
server.use(http.post("/api/auth/logout", () => {
logoutCalls += 1;
@@ -79,7 +79,7 @@ describe("authenticated shell permissions", () => {
permissions: ["session.use"],
}, false);
- expect(await screen.findByText("portal-user")).toBeInTheDocument();
+ await waitFor(() => expect(screen.queryByText("portal-user")).not.toBeInTheDocument());
expect(screen.queryByRole("button", { name: "Log out" })).not.toBeInTheDocument();
expect(logoutCalls).toBe(0);
});
diff --git a/frontend/src/shell/AppShell.tsx b/frontend/src/shell/AppShell.tsx
index d7097cd8..388ee9e3 100644
--- a/frontend/src/shell/AppShell.tsx
+++ b/frontend/src/shell/AppShell.tsx
@@ -716,16 +716,14 @@ export function AppShell({ canLogout }: AppShellProps) {
Human In The Loop
- {authenticatedUser && (
+ {authenticatedUser && canLogout && (
{authenticatedUser.displayName ?? authenticatedUser.subject}
- {canLogout && (
-
- )}
+
)}