WEB-205
Admin System: audit log viewer (filters, diffs, chain verify, export), integrations, account (2-step, phone alerts via Web Push, PWA, sign out everywhere)
Evidence
From logs/evidence/WEB-205/. Click a thumbnail for the full image.
Images (10)
Tests
$ cd apps/admin && pnpm build >/dev/null 2>&1 && ZOEN_EVIDENCE_TASK=WEB-205 pnpm exec playwright test tests/e2e/system.spec.ts tests/e2e/shell.spec.ts --workers=1 --reporter=line$ cd apps/admin && pnpm build >/dev/null 2>&1 && ZOEN_EVIDENCE_TASK=WEB-205 pnpm exec playwright test tests/e2e/system.spec.ts --workers=1 --reporter=line$ cd apps/admin && ZOEN_EVIDENCE_TASK=WEB-205 pnpm exec playwright test tests/e2e/system.spec.ts --workers=1 --reporter=line$ cd apps/admin && ZOEN_EVIDENCE_TASK=WEB-205 pnpm exec playwright test tests/e2e/system.spec.ts --workers=1 --reporter=lineNotes
2026-10-04 18:14 UTC · Evidence logs/evidence/WEB-205: audit (verify chain, filters, diffs, export), account. SECURITY FIX: access tokens stayed valid after 'sign out everywhere' until expiry (stateless JWT) → has_perm/current_staff now also require the token's auth session to exist (private.session_alive; pgTAP 120) so revoked sessions lose access on the next request. Phone alerts: Web Push (VAPID) with per-device subscriptions, dispatch to staff allowed to see each notification (pgTAP 100), service worker + installable PWA (192/512/maskable icons from the accepted emblem — a proper 1024px app icon should be an art request). Test infra: setup reuses still-valid sessions (<50 min, API-checked), serial + retries; long e2e runs go to the background (foreground shell was killed under load avg 100–130 from other projects).










