The .feature spec lagged shipped behaviour. Added three files, no duplication of existing scenarios: - registration.feature: new Dex subject -> registration gate (users + user_identities), returning subject straight through, account delete is tapir-side only and leaves other users intact, clean re-registration (ADR-012, ADR-013). - summarize_mode.feature: auto summarizes every new video; manual (default) leaves them unsummarized until queued; queued video is processed and the flag cleared (migration 006). - landing_page.feature: unauthenticated / -> /welcome, Get Started for guests, summary link + logout for authed users, logout -> /welcome. Scoped to built features only — no Vimeo/Whisper/billing scenarios. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
46 lines
2.2 KiB
Gherkin
46 lines
2.2 KiB
Gherkin
Feature: Register and manage a multi-user account
|
|
As one of a handful of trusted users
|
|
I want my own account, isolated from everyone else's
|
|
So that Tapir can serve several people from one deployment without leaking data
|
|
|
|
# Stage 1 (ADR-012): Dex authenticates, Tapir authorizes per user. A Dex subject
|
|
# with no users row is a new user and must register before reaching any data.
|
|
|
|
Scenario: A new Dex subject is routed to registration
|
|
Given I am authenticated by Dex with a subject that has no Tapir account
|
|
When I open any page that requires an account
|
|
Then I am routed to the registration page
|
|
And no summaries are shown until I register
|
|
|
|
Scenario: Registering creates the account and its identity mapping
|
|
Given I am authenticated by Dex with a subject that has no Tapir account
|
|
When I complete registration
|
|
Then a user row is created for me
|
|
And a user_identities row maps my Dex subject to that user
|
|
And I am taken into the app as a registered user
|
|
|
|
Scenario: A returning subject passes straight through
|
|
Given I am authenticated by Dex with a subject that already has a Tapir account
|
|
When I open the app
|
|
Then I am not asked to register again
|
|
And I see my own summaries
|
|
|
|
Scenario: Deleting an account removes only my data and leaves other users untouched
|
|
Given I am a registered user with summaries, a connected account, and recorded actions
|
|
And another user exists with their own summaries
|
|
When I delete my account
|
|
Then all of my rows are removed across every user-owned table
|
|
And my stored secret references are removed
|
|
And the other user's data remains intact
|
|
And my Dex identity is left intact
|
|
|
|
Scenario: A deleted user can register again as a fresh account
|
|
Given I deleted my Tapir account but my Dex identity still exists
|
|
When I sign in again
|
|
Then I am routed to the registration page as a new user
|
|
And registering creates a fresh user row with none of my old data
|
|
|
|
# Isolation is DB-enforced (Postgres RLS, ADR-012, migration 003): a user can never
|
|
# read or write another user's rows even if an application WHERE clause is wrong.
|
|
# Deletion is Tapir-side only — the shared Dex directory is never modified (ADR-013).
|