Skip to content

feat: real Cognito authentication with owner/manager/counter_staff roles - #14

Merged
Mahakisore7 merged 1 commit into
mainfrom
feat/cognito-auth-rbac
Sep 19, 2026
Merged

Mahakisore7 merged 1 commit into
mainfrom
feat/cognito-auth-rbac

Conversation

@Mahakisore7

Copy link
Copy Markdown
Contributor

Replaces the free-text ?shop_id=&counter_id= identity scheme with real sign-up/sign-in (Cognito User Pool), closing the cross-tenant gap crudTable.ts's own comments flagged (any shop_id was previously accepted from an unauthenticated client). Every REST route now sits behind a JWT authorizer; shop_id is derived from the verified token's claims, never trusted from the request. WebSocket $connect verifies the same token manually since API Gateway has no native WS JWT authorizer.

Self-signup makes you the "owner" of a new shop; owners invite manager/counter_staff accounts via a new POST /staff admin endpoint (AdminCreateUser, scoped to the inviter's own shop_id). Catalog writes (products/categories/suppliers) are owner/manager-only; counter staff keep full checkout/transactions access.

Frontend: AuthContext/cognito.ts drive sign-up, email confirmation, sign-in, and the forced-password-change flow for invited staff; App.tsx gates on auth status before showing the counter picker; StaffPage lets an owner invite staff and see role-gated nav.

Replaces the free-text ?shop_id=&counter_id= identity scheme with real
sign-up/sign-in (Cognito User Pool), closing the cross-tenant gap
crudTable.ts's own comments flagged (any shop_id was previously
accepted from an unauthenticated client). Every REST route now sits
behind a JWT authorizer; shop_id is derived from the verified token's
claims, never trusted from the request. WebSocket $connect verifies the
same token manually since API Gateway has no native WS JWT authorizer.

Self-signup makes you the "owner" of a new shop; owners invite
manager/counter_staff accounts via a new POST /staff admin endpoint
(AdminCreateUser, scoped to the inviter's own shop_id). Catalog writes
(products/categories/suppliers) are owner/manager-only; counter staff
keep full checkout/transactions access.

Frontend: AuthContext/cognito.ts drive sign-up, email confirmation,
sign-in, and the forced-password-change flow for invited staff;
App.tsx gates on auth status before showing the counter picker;
StaffPage lets an owner invite staff and see role-gated nav.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@Mahakisore7
Mahakisore7 merged commit 9288c35 into main Sep 19, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant