Skip to content

feat(portal): show one-time Formulus onboarding QR - #701

Merged
r0ssing merged 3 commits into
OpenDataEnsemble:devfrom
najuna-brian:feat/portal-formulus-onboarding-qr
Jul 14, 2026
Merged

r0ssing merged 3 commits into
OpenDataEnsemble:devfrom
najuna-brian:feat/portal-formulus-onboarding-qr

Conversation

@najuna-brian

@najuna-brian najuna-brian commented Jul 13, 2026 •

Copy link
Copy Markdown
Member
image

Summary

  • show a one-time Formulus onboarding handoff after admin user creation and password reset, including masked credentials, FRMLS v1 QR, copy controls, and PNG download
  • generate strong passwords client-side while allowing admins to reveal, replace, or regenerate them; add confirmation dialogs for password resets and user deletion
  • align the Synkronus delete-user route with the OpenAPI-generated portal client while retaining the legacy endpoint

Security

  • plaintext credentials remain only in transient React state and are cleared when the onboarding modal is dismissed
  • no password or QR payload is persisted in browser storage or returned by a new backend endpoint

Test plan

  • Build the portal production bundle with Vite
  • Type-check and lint the new portal QR utilities and onboarding component
  • Run go test ./internal/api ./internal/handlers
  • Create a user and confirm the one-time QR handoff appears
  • Reset a user password and confirm the reset warning and QR handoff
  • Delete a user through the portal
  • Scan the downloaded QR in Formulus on a physical device

Closes #694

Surface credentials only at creation or admin reset so admins can securely hand off a branded, downloadable Formulus configuration.
Register the documented delete endpoint while retaining the legacy route so portal deletes work without breaking older clients.
@najuna-brian
najuna-brian requested a review from r0ssing July 13, 2026 22:53

@r0ssing r0ssing left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great! Only comment is about the changes introduced in Synkronus (test + API), which I don't think should be part of this PR? (I can't even see that the new code in the portal even uses that endpoint, but I might've missed that ;-))

Comment thread synkronus/internal/api/api.go Outdated
Comment thread synkronus/internal/api/api_integration_test.go Outdated
Comment thread synkronus/internal/handlers/user.go Outdated
Keep the Synkronus API unchanged by routing portal deletions through the existing legacy endpoint.
@najuna-brian

Copy link
Copy Markdown
Member Author

Addressed in b483006. I removed the Synkronus API, handler, and test changes. The portal now uses the existing DELETE /api/users/delete/{username} endpoint, so user deletion still works without changing the backend.

@najuna-brian
najuna-brian requested a review from r0ssing July 14, 2026 07:03

@r0ssing r0ssing left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great! Thanks @najuna-brian !

@r0ssing
r0ssing merged commit 433f512 into OpenDataEnsemble:dev Jul 14, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Synkronus Portal] Show Formulus onboarding QR in portal after user creation (and admin password reset)

2 participants