Skip to content

Impersonation is invisible in the console — no banner, no "Stop impersonating" control, and no Impersonate entry point #4304

Description

@huangyiirene

Symptom

With an impersonation server-confirmed in the very browser context (an in-page get-session returns the target's email and a populated session.impersonatedBy), the console gives the operator no sign they are impersonating anyone:

  • /_console/home renders "Good morning, Dev Admin." with avatar DA — the admin's identity, not the target's.
  • The DOM contains no banner, no "Stop impersonating" control, and the impersonated user's name appears nowhere.
  • The console also offers no Impersonate entry point at all.

Reproduced twice in fresh contexts with hard reload + networkidle + 3 s settle. Support sessions are silent in this build.

Root cause

The console never reads or surfaces the impersonation state on the session. Confirmed against objectui origin/main (checked as part of filing): a case-insensitive search for impersonat across packages/**/src/** returns exactly one hit — an unrelated comment in packages/app-shell/src/views/studio-design/ObjectApiPanel.tsx. There is no impersonatedBy handling, no impersonation banner, no "Stop impersonating" control, and no Impersonate entry point anywhere in the console source. The greeting itself lives in packages/app-shell/src/console/home/HomePage.tsx (pickGreetingKey) and reads the admin's own identity; the session plumbing that would carry impersonatedBy is in packages/app-shell/src/console/ConsoleShell.tsx / packages/auth/src/AuthProvider.tsx / packages/auth/src/createAuthClient.ts, none of which consult the impersonation fields.

So this is not already fixed upstream — it is genuinely absent on origin/main.

Expected: while impersonating, the console should (a) show a persistent banner naming the impersonated user, (b) offer a "Stop impersonating" control, and (c) ideally provide an Impersonate entry point for admins.

Reproduction

  1. As a better-auth admin, start an impersonation of a target user (server-side).
  2. In that browser context, confirm via in-page get-session that the session returns the target's email and a populated session.impersonatedBy.
  3. Load /_console/home → greeting reads "Good morning, Dev Admin." (the admin), no banner, no "Stop impersonating" control, target's name nowhere in the DOM.

Source

Extracted from the QA run objectstack-ai/objectstack#7663 (framework 92f26f75, console 09987b6). This is the console half of the admin-lifecycle-operations FAIL; the objectstack half is filed as objectstack-ai/objectstack#7724.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpm:queue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions