Goal
Model the User and PermissionProfile aggregates, the effective access calculation and the login suggestion, test-first, using the value objects from #4.
Scope
User (aggregate root, references profiles by id only)
- Status lifecycle
Pending → Active ↔ Inactive through behavior methods, never setters: activation, deactivation (USR-16, USR-17: status, date and author of the deactivation), reactivation (USR-18: back to Active if a password was ever created, otherwise back to Pending).
- Nobody deactivates themselves; the Admin is never deactivated (USR-19).
- Profiles may be empty; unknown ids are discarded by the caller (USR-13, USR-21).
- The Admin system record cannot change and always keeps the Gerenciador profile (USR-23, USR-24). Fixed ids in a
SystemIds class.
PermissionProfile (aggregate root)
- A new profile starts with every screen
Denied (PERM-18); levels are changed through methods such as SetLevel.
- The Gerenciador system profile cannot change or be deleted, and its levels are computed, not stored (PERM-22, PERM-23).
Effective access (domain service, PERM-05, PERM-06, PERM-07)
- Highest level among the user's profiles, screen by screen; missing screen =
Denied; no profiles = Denied everywhere; unknown profile id ignored; the Gerenciador profile gives Manager everywhere, including new screens.
Login suggestion (pure domain service, USR-14, USR-15)
- First and last name, no accents, lowercase, dot-separated; numeric suffix when taken (the set of taken logins is passed in as a parameter); special cases of USR-15.
Out of scope
Uniqueness against the database (#7, #10, #11), persistence, endpoints.
Done when
References
docs/product/features/users.md, docs/product/features/permission-profiles.md, ADR-0006, ADR-0016, ADR-0022, ADR-0024, docs/agents/guides/architecture.md.
Goal
Model the
UserandPermissionProfileaggregates, the effective access calculation and the login suggestion, test-first, using the value objects from #4.Scope
User(aggregate root, references profiles by id only)Pending → Active ↔ Inactivethrough behavior methods, never setters: activation, deactivation (USR-16, USR-17: status, date and author of the deactivation), reactivation (USR-18: back toActiveif a password was ever created, otherwise back toPending).SystemIdsclass.PermissionProfile(aggregate root)Denied(PERM-18); levels are changed through methods such asSetLevel.Effective access (domain service, PERM-05, PERM-06, PERM-07)
Denied; no profiles =Deniedeverywhere; unknown profile id ignored; the Gerenciador profile givesManagereverywhere, including new screens.Login suggestion (pure domain service, USR-14, USR-15)
Out of scope
Uniqueness against the database (#7, #10, #11), persistence, endpoints.
Done when
References
docs/product/features/users.md,docs/product/features/permission-profiles.md, ADR-0006, ADR-0016, ADR-0022, ADR-0024,docs/agents/guides/architecture.md.