Tela de inscrição MFA e controle de limite PHI em modo deus

Featurekamo-internal
Shipped
4 de agosto de 2026 às 03:58 UTC
Author
Kamo
Commit
dc2cba8

Two settings surfaces for backends that had none. MFA enrollment (settings → my profile → Sign-in Security, self only). SecurityService's /api/security/mfa endpoints have been complete and entirely unreachable, so MFA existed and nobody on the platform could turn it on. The tab is self-only because those endpoints resolve the user from the caller's own session and take no user parameter — an admin opening someone else's profile would be enrolling their own authenticator on that screen. The QR code uses qrcode.react, already a dependency; no package was added. The secret is shown next to it regardless, because an authenticator app on the same device as the browser cannot scan the screen it is covering. Two failure paths get first-class handling rather than a generic error. A 409 means a confirmed factor already exists and says so, with the remedy (an administrator reset) — telling the user to retry would send them back into the one action that cannot succeed. A wrong confirmation code keeps the pending enrollment: the secret is displayed once, so discarding it would mean deleting the authenticator entry and rescanning, and the server's pending enrollment would still be there, so the retry would come back 409 and strand them. Recovery codes are shown once and cannot be reissued. The dialog cannot be dismissed by escape, backdrop or a close button; Done unlocks only after the codes have been copied or downloaded AND the warning acknowledged. Both are required: a checkbox alone is clicked reflexively, and a clipboard alone is overwritten by the next copy — and nothing looks wrong until the day the user loses their phone. PHI boundary (settings → security → Health Data, god-eligible only). The tab is visible to god-eligible operators and the control inside requires god mode actually switched on, which SecurityService re-checks; eligibility alone is not activation. It never flips without first listing the modules that stop working — that list comes from the server, derived from PhiModule through PhiTenantGuard, so it cannot drift from what is enforced. A 503 is surfaced as "the change was not applied because it could not be recorded", because that is what happened. Decision logic lives in app/lib/security so vitest can reach it; the components hold rendering only. Verified: npx vitest run — 329 tests, 32 files, all passing (43 of them new). npx tsc --noEmit reports only three errors in **************** an untracked file from another session in this tree, in none of the files here.

All changes

Como o que vês no transporte?

Cada uma dessas atualizações pousa automaticamente em seu espaço de trabalho. Comece grátis e veja crescer semana após semana.

Começar Livre Para SempreVer Preços