Skip to content

Aurora: the sign-in methods page (#132, phase 6) - #138

Draft
sneridagh wants to merge 2 commits into
issue-132-phase-5from
issue-132-phase-6
Draft

sneridagh wants to merge 2 commits into
issue-132-phase-5from
issue-132-phase-6

Conversation

@sneridagh

Copy link
Copy Markdown
Member

Sixth phase of #132, stacked on #137. Draft: please don't merge. Each phase gets its own PR, built on the previous one, and none is merged until the whole series has been reviewed.

The first of the Aurora pages planned in the comment on #132: sign-in methods, at /identities, the same page as Volto's.

The panel moves to core

IdentitiesList and ProfileEmails move from volto-identity to identity-core, with their tests, stories, fixtures and translations. They follow the phase 2 pattern.

Change Why
react-intl → defineMessages from #i18n, useIdentityUI().t Core imports no i18n library
profileUrl → profileEditHref, rendered with IdentityUI.Link The edit form is a frontend route: Volto's is <profile>/edit (with flattenToAppURL), Aurora's /@@edit<profile>
SCSS → CSS, compiled with sass; comment blocks preserved Aurora has no Sass compiler
.identity-tabs styles moved into core's styles.css The panel wears them. Volto's account page still does too, and gets them from core

Volto. The Identities container keeps its Redux state, renders core's panel inside VoltoIdentityUI, and builds the edit href.

Tests. The 30 panel tests moved: core 282 → 312, Volto 664 → 634. One changed: the profile-link test now checks the href it is given.

Translations. The 21 messages moved with their translations, in de, es and pt_BR. They are now in core's catalogues, and in Aurora's through pnpm i18n.

Aurora's /identities

Piece What it does
routes/identities.tsx Behind requireAuthCookie. The loader reads @identities?expand=login-providers and @my-profile as the user. A session the backend refuses sends the user to /login?came_from=/identities with the cookie cleared. The action handles link, unlink, verify and prefer
Linking POST @identities with the session, which answers with the provider's authorize URL and the flow cookie. The action redirects there, relaying the cookie. The provider sends the browser to the callback, which sends the session, so the backend links instead of signing in
Preferring an address Reads the profile again on the server and PATCHes the whole reordered list, as Volto does
slots/IdentityTools.tsx A Sign-in methods link in Aurora's authenticatedTools slot, beside Log out
lib/routes.ts addRouteUnder Adds the page under @plone/publicui's layout, beside its search page, so it has the site's header and the way back out
lib/api.ts callBackend One way to call the backend through the virtual-host URL, as the user

Fixed on the way

  • Where a completed link went. The callback sent a completed link to /. The backend's linked answer carries no came_from, and phase 3 relied on one. It now goes to /identities, as Volto's callback does. The acceptance test below caught it. A unit test (routes/callback.test.ts) was seen failing with the old code.
  • Volto's tests ran core's React Aria on Aurora's React. After an Aurora install, identity-core/node_modules/react-aria-components is Aurora's copy. Core's components now use React Aria directly, so Volto's tests failed with a null useContext. volto-identity/vitest.config.mjs deduplicates core's peers, as razzle.extend.js does for webpack. AGENTS.md says so.

Acceptance tests

frontend/aurora/acceptance/tests/identities.spec.ts. The Dex fixture's second static client, plone-second, which the backend's linking tests use, is registered as a second provider for this file only. The steps are now shared in acceptance/dex.ts.

Test Checks
Signed out /identities sends to /login
From the user menu Sign-in methods leads to the page, inside the site's frame (Log out still there)
Link and remove One identity, whose Remove is disabled as the last way in. Linking Dex (second) goes through Dex and back to /identities with two identities; removing it leaves one

All eight acceptance tests pass locally, twice in a row against the same server. Not run in CI yet.

Checks

Check Result
Tests Core 312, Volto 634, Aurora add-on 31
A new test, seen red The callback's link redirect
make -C frontend lint, make aurora-lint, both typechecks Pass
ci-i18n, both harnesses Pass
Storybook; Volto pnpm build; make aurora-build Pass. The Volto bundle carries React 18.2.0 only
make docs-build; Vale Pass; 0 errors

Docs

concepts/frontends.md gains "Where Aurora's other pages go". Its "What Aurora does not have yet" now lists what is left.

- Move the sign-in methods panel (IdentitiesList, ProfileEmails) into
  identity-core, with its tests, stories, fixtures and translations. The
  profile's edit link becomes a ready href each frontend builds, and the
  tab styles move to core's stylesheet.
- Aurora's /identities, under publicui's layout: the loader lists the
  identities and the profile's addresses as the user, the action links,
  unlinks, verifies and reorders. Linking redirects to the provider with
  the flow cookie. A Sign-in methods entry in the authenticatedTools slot.
- The callback now returns a completed link to /identities. The backend's
  link answer has no came_from, so it used to land on the site root.
- Volto's Vitest config deduplicates core's peers: core's React Aria
  resolved to Aurora's copy after an Aurora install.
- Playwright: the page needs a session, is reached from the user menu,
  and links a second Dex client and removes it again.

Refs #132

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant