Slice 5 of #788. Depends on #795 and #798.
This slice adds two views of the same data. They show what is connected and let a person cut it off.
The user's own view, on the Account page
This view lives beside change-password on web/src/routes/AccountPage.tsx, the self-service page. It does not go on UsersPage.tsx, which is the Owner-only admin screen for managing other people.
It shows each connected assistant with:
- the app's name
- what it can do (the granted permissions, in the same plain words the consent screen used)
- when it was connected
- last used, the signal that tells a user a connection is dormant and worth removing
- a Disconnect action
The Owner's farm-wide view
It lists every connection on the farm, across all users, and lets the Owner revoke any of them.
The justification is worth stating in the UI or the docs. Owners can already reset any user's password and disable any user, so revoking a connection is strictly less invasive than powers they already hold. This view prevents a departed employee's assistant from staying connected with nobody able to see it.
Behaviour
Disconnecting takes effect on the next request. #788 chose reference tokens for exactly this reason. Verify it rather than assume it. Revoke a connection, then assert that the next call fails.
Also
This slice changes what a user sees, so the PR carries before/after screenshots from a stack rebuilt at the head under review. After-only is fine for net-new screens. The same PR updates specs/product/GLOSSARY.md and the SPA Help page.
Done when
A user can see and disconnect their own connections; an Owner can see and revoke any on the farm; a revoked connection stops working on the next call.
Slice 5 of #788. Depends on #795 and #798.
This slice adds two views of the same data. They show what is connected and let a person cut it off.
The user's own view, on the Account page
This view lives beside change-password on
web/src/routes/AccountPage.tsx, the self-service page. It does not go onUsersPage.tsx, which is the Owner-only admin screen for managing other people.It shows each connected assistant with:
The Owner's farm-wide view
It lists every connection on the farm, across all users, and lets the Owner revoke any of them.
The justification is worth stating in the UI or the docs. Owners can already reset any user's password and disable any user, so revoking a connection is strictly less invasive than powers they already hold. This view prevents a departed employee's assistant from staying connected with nobody able to see it.
Behaviour
Disconnecting takes effect on the next request. #788 chose reference tokens for exactly this reason. Verify it rather than assume it. Revoke a connection, then assert that the next call fails.
Also
This slice changes what a user sees, so the PR carries before/after screenshots from a stack rebuilt at the head under review. After-only is fine for net-new screens. The same PR updates
specs/product/GLOSSARY.mdand the SPA Help page.Done when
A user can see and disconnect their own connections; an Owner can see and revoke any on the farm; a revoked connection stops working on the next call.