Files
cameleer-saas/ui/CLAUDE.md
hsiegeln e9e18f6c38
Some checks failed
CI / build (push) Failing after 2m1s
CI / docker (push) Has been skipped
CI / build (pull_request) Failing after 1m46s
CI / docker (pull_request) Has been skipped
docs: update CLAUDE.md for account package, vendor admins, and shared components
- Add account/ package to Key Packages table
- Add VendorAdminService/Controller to vendor/ package
- Note TenantPortalService delegation to AccountService
- Update ui/CLAUDE.md: AccountSettingsPage, VendorAdminsPage,
  Administrators sidebar, user menu dropdown, shared components

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-27 15:09:41 +02:00

3.1 KiB

Frontend

React 19 SPA served at /platform/* by the Spring Boot backend.

Core files

  • main.tsx — React 19 root
  • router.tsx/vendor/* + /tenant/* with RequireScope guards, LandingRedirect that waits for scopes (redirects to /onboarding if user has zero orgs), /register route for OIDC sign-up flow, /onboarding route for self-service tenant creation
  • Layout.tsx — persona-aware sidebar: vendor sees expandable "Vendor" section (Tenants, Audit Log, Certificates, Metrics, Infrastructure, Email Connector, Administrators, Logto Console), tenant admin sees Dashboard/License/SSO/Team/Audit/Settings. TopBar user dropdown includes "Account Settings" link.
  • OrgResolver.tsx — merges global + org-scoped token scopes (vendor's platform:admin is global)
  • config.ts — fetch Logto config from /platform/api/config

Auth hooks

  • auth/useAuth.ts — auth hook (isAuthenticated, logout, signIn)
  • auth/useOrganization.ts — Zustand store for current tenant
  • auth/useScopes.ts — decode JWT scopes, hasScope()
  • auth/ProtectedRoute.tsx — guard (redirects to /login)
  • auth/LoginPage.tsx — redirects to Logto OIDC sign-in
  • auth/RegisterPage.tsx — redirects to Logto OIDC with firstScreen: 'register'

Pages

  • Onboarding: OnboardingPage.tsx — self-service trial tenant creation (org name + slug), shown to users with zero org memberships after sign-up
  • Shared pages: AccountSettingsPage.tsx/settings/account, any authenticated user. Profile, password (with current-password verification), TOTP MFA, passkeys. Composes shared components from components/account/.
  • Vendor pages: VendorTenantsPage.tsx, CreateTenantPage.tsx, TenantDetailPage.tsx, VendorAuditPage.tsx, CertificatesPage.tsx, InfrastructurePage.tsx, EmailConfigPage.tsx (SMTP connector config, registration toggle, test email), VendorAdminsPage.tsx (platform admin list, invite/create, remove, reset password/MFA)
  • Tenant pages: TenantDashboardPage.tsx (restart + upgrade server), TenantLicensePage.tsx, SsoPage.tsx, TeamPage.tsx (reset member passwords), TenantAuditPage.tsx, SettingsPage.tsx (imports shared account components, plus tenant-specific auth policy, MFA enforcement toggle, server admin password)

Custom Sign-in UI (ui/sign-in/)

Separate Vite+React SPA replacing Logto's default sign-in page. Built as custom Logto Docker image — see docker/CLAUDE.md for details.

  • SignInPage.tsx — sign-in + registration form with @cameleer/design-system components. Three modes: signIn (email/username + password), register (email + password + confirm), verifyCode (6-digit email verification). Reads first_screen=register from URL query params to determine initial view. Registration is disabled by default — the vendor admin enables it via the Email Connector page after configuring SMTP.
  • experience-api.ts — Logto Experience API client. Sign-in: init -> verify password -> identify -> submit. Registration: init Register -> send verification code -> verify code -> add password profile -> identify -> submit. Auto-detects email vs username identifiers.