Flow H, three screens behind a role check: find an account, work the ingestion error queue, read and export the audit log. Superadmins can change a role, never their own. The error queue merges ingest errors and dead jobs into one table with a cursor that pages both sources; only a job can be retried and only an ingest row resolved, with a note that migration 003 gives it somewhere to live. writeAudit no longer defaults a missing subject to the actor, which had been recording a user search as staff looking themselves up. Omitting the subject still means acting on yourself; null now means the action has no subject, which is what a search, a retry and an export are. Reading the log is not audited. Exporting it is: a copy leaving the building is a different act from looking. e2e/global-setup.ts asks for every screen once before the suite starts, so a dev server's first-request compile is paid before the first test rather than by it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
23 lines
706 B
TypeScript
23 lines
706 B
TypeScript
import { isApiError } from '@impuestos/contracts';
|
|
import { setRequestLocale } from 'next-intl/server';
|
|
import { serverApi } from '@/lib/api-server';
|
|
import { UserOverview } from './user-overview';
|
|
|
|
export default async function UsuarioPage({
|
|
params,
|
|
}: {
|
|
params: Promise<{ locale: string; id: string }>;
|
|
}) {
|
|
const { locale, id } = await params;
|
|
setRequestLocale(locale);
|
|
|
|
// Role management is superadmin only, so the viewer's role decides what renders.
|
|
const api = await serverApi();
|
|
const session = await api.getSession().catch((error: unknown) => {
|
|
if (isApiError(error)) return null;
|
|
throw error;
|
|
});
|
|
|
|
return <UserOverview id={id} viewerRole={session?.role ?? 'user'} />;
|
|
}
|