phase-6: the staff console, and a log that says who did what

Flow H, three screens behind a role check: find an account, work the
ingestion error queue, read and export the audit log. Superadmins can
change a role, never their own.

The error queue merges ingest errors and dead jobs into one table with a
cursor that pages both sources; only a job can be retried and only an
ingest row resolved, with a note that migration 003 gives it somewhere
to live.

writeAudit no longer defaults a missing subject to the actor, which had
been recording a user search as staff looking themselves up. Omitting
the subject still means acting on yourself; null now means the action
has no subject, which is what a search, a retry and an export are.

Reading the log is not audited. Exporting it is: a copy leaving the
building is a different act from looking.

e2e/global-setup.ts asks for every screen once before the suite starts,
so a dev server's first-request compile is paid before the first test
rather than by it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-04 21:55:59 +00:00
co-authored by Claude Opus 5
parent 6620650e9e
commit 4c39926483
39 changed files with 2767 additions and 11 deletions
+11
View File
@@ -4,6 +4,7 @@ import {
DependentInput,
NotificationPrefsInput,
ProfileInput,
UserRole,
} from '@impuestos/contracts';
import { Hono } from 'hono';
import type { z } from 'zod';
@@ -28,6 +29,16 @@ export function meRoutes(deps: AppDeps): Hono<AppEnv> {
const routes = new Hono<AppEnv>();
const db = deps.handle.db;
// Who you are, for a client that needs the role before it renders (the admin console).
routes.get('/session', (c) => {
const user = requireUser(c);
// The session carries whatever string the user row holds. A value outside the enum
// would fail the client's schema and take a page down, so it reads as the least
// privileged role instead.
const role = UserRole.safeParse(user.role);
return c.json({ id: user.id, email: user.email, role: role.success ? role.data : 'user' });
});
// 404 until setup is complete: the client routes to onboarding (CONTRACTS.md section 3).
routes.get('/profile', async (c) => {
const user = requireUser(c);