Repository navigation
Conversation
- ApplicationsPanel moves to identity-core, with its 22 tests, stories and
translations. Semantic UI's Table and Button become plain elements
wearing Semantic UI's classes, so Volto's theme still draws them; Aurora
draws them in its own stylesheet. Its icons come from IdentityUI, which
gains back, details and remove, and a locale for dates.
- identity-core fills plural messages ({count, plural, ...}) in the
reader's language, so the panel's ICU messages work without react-intl.
- ConfirmDialog in identity-core, on React Aria's modal dialog.
- Aurora's /applications: the loader reads @oauth-grants, the action
withdraws a grant after the dialog asks. The Applications entry is
offered only where @oauth-grants answers, asked from the server and
kept for IDENTITY_FEATURE_TTL seconds (300 by default) per backend.
- Playwright: no entry without the authorization server; with it,
installed through @addons, the entry leads to the empty list.
Refs #132
This was referenced Oct 4, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Eighth phase of #132, stacked on #139. Draft: please don't merge. Each phase gets its own PR, built on the previous one, and none is merged until the whole series has been reviewed.
Applications, from the plan: the OAuth clients a user has authorized, and withdrawing one, on sites running the
[server]layer.The panel moves to core
ApplicationsPanelmoves toidentity-corewith its 22 tests (core 324 → 356 with the additions below; Volto 634 → 612), stories,GRANTSfixture and translations. Three things core lacked:{count, plural, one {# field} other {# fields}}, and the "up to N minutes" noteinterpolatefills plural messages withIntl.PluralRulesin the reader's language:=N, the locale's category, thenother, with#as the number. 6 tests, including a language with afewcategory. Aurora'stranslateWithpasses i18next's language, tested with a real i18next and a German pluralintl.formatDateIdentityUI.locale, Volto'sintl.localeand i18next's language in Aurora, andIntl.DateTimeFormatTableandButton, and three Volto icons<table className="ui selectable compact table">and<button className="ui basic icon button">, so Volto's theme draws them as before, andAuroraIdentityUI.cssdraws them in Quanta's colours.IdentityIconsgainsback,detailsandremove: Volto's own icons at their old sizes, Quanta's in AuroraVolto's page. It keeps its Redux state, its Semantic UI confirm modal and its toasts, and renders core's panel inside
VoltoIdentityUI. I did not compare the Volto page by eye before and after. The class names are Semantic UI's own, so its look should not change, but that is worth a look in review.Aurora's
/applicationsroutes/applications.tsxrequireAuthCookie. The loader reads@oauth-grants. The action DELETEs@oauth-grants/<client>after core's newConfirmDialogasks, then says "Access withdrawn" where Volto shows a toastConfirmDialog(core)ModalOverlay/Modal/Dialog role="alertdialog": focus held inside, Escape cancels. Volto keeps its own modal@oauth-grantsanswers, as in Volto. The[server]layer is the only publisher, and core cannot depend on it to say whether it is installedlib/features.tsIDENTITY_FEATURE_TTLseconds, 300 by default. A 401 is about the session, not the site, so it is not kept. 6 testsAcceptance tests
applications.spec.ts. The acceptance site runs without the authorization server, as most sites do. The test installs and uninstallspas.plugins.identity.serverthrough plone.restapi's@addons, with no backend change. Aurora runs withIDENTITY_FEATURE_TTL=0there, locally and in CI, so the install is seen on the next page.A grant can only exist after the user has gone through the consent screen, which is phase 9. So listing and withdrawing a real grant is left for that phase's acceptance test, which can do the whole OAuth flow through Aurora. The panel's 22 unit tests cover the listing and the withdrawal.
All 11 acceptance tests pass locally, twice. Not run in CI yet.
Checks
make -C frontend lint,make aurora-lint, both typechecksci-i18n, both harnessespnpm build;make aurora-buildmake docs-build; Valeconcepts/frontends.mdgains "The applications page". Its "What Aurora does not have yet" is now the consent screen and the control panels.