Phase 5: platform feature-flags CRUD, impersonation, billing catalogue

Three new platform screens on top of the Phase 1-4 work.

Feature flags (/feature-flags) — platform-wide flag registry. New route +
lib/arcadia/feature-flags.ts, capability platform.feature_flags, nav under
Automation. List/create/edit/delete with a per-row default toggle; pairs with
the Phase-4 per-tenant override tab.

Impersonation — "Impersonate" action on active users. Entirely client-side
token swap in session.ts (beginImpersonation parks the operator's session +
API token and swaps to the impersonation token; endImpersonation restores it),
with a sticky "Viewing as <email> — Stop" banner in the shell driven by the
JWT's impersonated_by claim. Stop is client-side because the impersonation
token carries the target's roles and can't reach the admin-gated /stop
endpoint; impersonation is stateless JWT so restoring the parked token is
sufficient.

Billing (/billing) — replaced the coming-soon stub with the real plan
catalogue from GET /billing/plans (lib/arcadia/billing.ts). Per-tenant plan
assignment stays on the tenant detail page; Entitlements + Apps remain honestly
marked "Soon".

Verified in-browser with real backend; typecheck adds zero errors (36→36).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jules
2026-07-14 14:04:09 +10:00
parent 7415b40240
commit af2c8d6663
10 changed files with 788 additions and 51 deletions

View File

@@ -109,3 +109,41 @@ export async function setUserStatus(
): Promise<User> {
return updateUser(arcadia, id, { status })
}
// --- Impersonation ---
// The operator (platform/tenant admin) can act as another user for support.
// `startImpersonation` returns a token scoped to the target; the client swaps
// to it (see session.beginImpersonation). Stopping is a client-side restore of
// the operator's parked session — the /stop endpoint can't be reached with the
// impersonation token (it lacks admin), so we don't rely on it.
export interface CanImpersonate {
can_impersonate: boolean
user: Pick<User, "id" | "email" | "status"> & { first_name?: string; last_name?: string }
}
export interface ImpersonationToken {
access_token: string
impersonated_by: string
expires_in: number
}
export async function canImpersonate(
arcadia: ArcadiaClient,
userId: string,
): Promise<CanImpersonate> {
const res = await arcadia.GET<{ data: CanImpersonate }>(
`/api/v1/admin/impersonate/${userId}/can-impersonate`,
)
return res.data
}
export async function startImpersonation(
arcadia: ArcadiaClient,
userId: string,
): Promise<ImpersonationToken> {
const res = await arcadia.POST<{ data: ImpersonationToken }>(
`/api/v1/admin/impersonate/${userId}`,
)
return res.data
}