Skip to content

Aurora: the applications page (#132, phase 8) - #140

Draft
sneridagh wants to merge 1 commit into
issue-132-phase-7from
issue-132-phase-8
Draft

sneridagh wants to merge 1 commit into
issue-132-phase-7from
issue-132-phase-8

Conversation

@sneridagh

Copy link
Copy Markdown
Member

Eighth phase of #132, stacked on #139. Draft: please don't merge. Each phase gets its own PR, built on the previous one, and none is merged until the whole series has been reviewed.

Applications, from the plan: the OAuth clients a user has authorized, and withdrawing one, on sites running the [server] layer.

The panel moves to core

ApplicationsPanel moves to identity-core with its 22 tests (core 324 → 356 with the additions below; Volto 634 → 612), stories, GRANTS fixture and translations. Three things core lacked:

Volto had Core now has
react-intl's ICU plurals: {count, plural, one {# field} other {# fields}}, and the "up to N minutes" note interpolate fills plural messages with Intl.PluralRules in the reader's language: =N, the locale's category, then other, with # as the number. 6 tests, including a language with a few category. Aurora's translateWith passes i18next's language, tested with a real i18next and a German plural
intl.formatDate IdentityUI.locale, Volto's intl.locale and i18next's language in Aurora, and Intl.DateTimeFormat
Semantic UI's Table and Button, and three Volto icons A plain <table className="ui selectable compact table"> and <button className="ui basic icon button">, so Volto's theme draws them as before, and AuroraIdentityUI.css draws them in Quanta's colours. IdentityIcons gains back, details and remove: Volto's own icons at their old sizes, Quanta's in Aurora

Volto's page. It keeps its Redux state, its Semantic UI confirm modal and its toasts, and renders core's panel inside VoltoIdentityUI. I did not compare the Volto page by eye before and after. The class names are Semantic UI's own, so its look should not change, but that is worth a look in review.

Aurora's /applications

Piece What it does
routes/applications.tsx Behind requireAuthCookie. The loader reads @oauth-grants. The action DELETEs @oauth-grants/<client> after core's new ConfirmDialog asks, then says "Access withdrawn" where Volto shows a toast
ConfirmDialog (core) React Aria's ModalOverlay/Modal/Dialog role="alertdialog": focus held inside, Escape cancels. Volto keeps its own modal
The Applications entry Beside Sign-in methods, only where @oauth-grants answers, as in Volto. The [server] layer is the only publisher, and core cannot depend on it to say whether it is installed
lib/features.ts Asks that from the server, and keeps the answer per backend for IDENTITY_FEATURE_TTL seconds, 300 by default. A 401 is about the session, not the site, so it is not kept. 6 tests

Acceptance tests

applications.spec.ts. The acceptance site runs without the authorization server, as most sites do. The test installs and uninstalls pas.plugins.identity.server through plone.restapi's @addons, with no backend change. Aurora runs with IDENTITY_FEATURE_TTL=0 there, locally and in CI, so the install is seen on the next page.

Test Checks
Without the server Sign-in methods in the header, no Applications
With it Applications leads to the page, which says nothing is authorized yet

A grant can only exist after the user has gone through the consent screen, which is phase 9. So listing and withdrawing a real grant is left for that phase's acceptance test, which can do the whole OAuth flow through Aurora. The panel's 22 unit tests cover the listing and the withdrawal.

All 11 acceptance tests pass locally, twice. Not run in CI yet.

Checks

Check Result
Tests Core 356, Volto 612, Aurora add-on 44
make -C frontend lint, make aurora-lint, both typechecks Pass
ci-i18n, both harnesses Pass. Every moved message kept its translations; no new message needed one
Storybook; Volto pnpm build; make aurora-build Pass
make docs-build; Vale Pass; 0 errors

concepts/frontends.md gains "The applications page". Its "What Aurora does not have yet" is now the consent screen and the control panels.

- ApplicationsPanel moves to identity-core, with its 22 tests, stories and
  translations. Semantic UI's Table and Button become plain elements
  wearing Semantic UI's classes, so Volto's theme still draws them; Aurora
  draws them in its own stylesheet. Its icons come from IdentityUI, which
  gains back, details and remove, and a locale for dates.
- identity-core fills plural messages ({count, plural, ...}) in the
  reader's language, so the panel's ICU messages work without react-intl.
- ConfirmDialog in identity-core, on React Aria's modal dialog.
- Aurora's /applications: the loader reads @oauth-grants, the action
  withdraws a grant after the dialog asks. The Applications entry is
  offered only where @oauth-grants answers, asked from the server and
  kept for IDENTITY_FEATURE_TTL seconds (300 by default) per backend.
- Playwright: no entry without the authorization server; with it,
  installed through @addons, the entry leads to the empty list.

Refs #132

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant