WEB-204
Admin System: staff list/invite/roles/disable/MFA reset, accept-invite flow, owner bootstrap command, role × permission matrix
Evidence
From logs/evidence/WEB-204/. Click a thumbnail for the full image.
Images (11)











Tests
$ cd apps/admin && pnpm build >/dev/null 2>&1 && ZOEN_EVIDENCE_TASK=WEB-204 pnpm exec playwright test tests/e2e/staff.spec.ts tests/e2e/shell.spec.ts --reporter=line$ cd packages/db && node --test tests/bootstrap.int.test.mjsNotes
2026-10-04 17:16 UTC · Evidence logs/evidence/WEB-204: enrol screen, staff list, roles matrix. Owner bootstrap: `pnpm admin:bootstrap-owner` (owner runs; hidden password prompt; refuses a second real owner without --add; integration-tested with @zoen.test). Invites: service-key invite e-mail (Mailpit locally) with custom template → /login/accept (token spent on submit, not on open) → password → TOTP enrol → activate_self. Roles/status/MFA reset are critical (reason + step-up); disable also bans at the auth server; last active owner protected (pgTAP 090). Stack restarted to load the invite template.
