Skip to content

Accounts App — Change Log

This log tracks software changes for this area.


Current status

Item Status Notes
Active development Open Workforce enrichment + service layer completed
Next release target TBA Stabilization + workforce extensions
Known risk Medium Auth/session + invite lifecycle critical paths

Recent changes (newest first)

Date Type Summary Impact Reference
2026-04-13 Refactor Moved auth business logic to service layer (services/auth.py) Medium N/A
2026-04-13 Refactor Moved invite lifecycle logic to service layer (services/invite.py) Medium N/A
2026-04-13 Feature Added identifier-based login (username OR email) Low N/A
2026-04-13 Feature Implemented full device + session lifecycle (logout, revoke, logout-all) Medium N/A
2026-04-13 Feature Added invite lifecycle: create, preview, accept, resend, cancel High N/A
2026-04-13 Feature Added workforce profile enrichment (manager, travel, capacity fields) Medium N/A
2026-04-13 Refactor Standardized serializers into domain folders (serializers/auth, devices, etc.) Low N/A
2026-04-13 Refactor Reorganized views into domain-based modules (views/auth, views/invites, etc.) Low N/A
2026-04-13 Feature Added structured test layers (API vs services vs models) Medium N/A
2026-04-13 Feature Added MkDocs documentation (models, serializers, services, views, tasks, urls, tests) Low N/A

Open items and status

ID Title Status Priority Owner Target Reference
ACCOUNTS-001 Add workforce availability (time-off / absences) model Open P1 Unassigned TBA
ACCOUNTS-002 Add workforce certifications with expiry alerts Open P1 Unassigned TBA
ACCOUNTS-003 Add manager hierarchy endpoints (team tree / reporting lines) Open P2 Unassigned TBA
ACCOUNTS-004 Add invite management endpoints (list/resend/cancel via API) Open P1 Unassigned TBA
ACCOUNTS-005 Add device/session cleanup job (expired sessions) Open P2 Unassigned TBA
ACCOUNTS-006 Add audit logging for auth + invite actions Open P1 Unassigned TBA
ACCOUNTS-007 Add rate limit config defaults for all throttled views Open P2 Unassigned TBA
ACCOUNTS-008 Add me/access endpoint (effective permissions snapshot) Open P2 Unassigned TBA
ACCOUNTS-009 Improve skill model with tagging / hierarchy Open P3 Unassigned TBA
ACCOUNTS-010 Add soft-delete or deactivation strategy for users Open P2 Unassigned TBA

Known bugs

ID Symptom Severity Status Workaround Reference
BUG-ACCOUNTS-001 Missing DRF throttle rates causes runtime errors in tests Low Mitigated Monkeypatch throttles in tests
BUG-ACCOUNTS-002 DeviceSession not auto-cleaned for expired refresh tokens Medium Open Manual logout-all
BUG-ACCOUNTS-003 Invite duplicate detection edge case with race conditions Medium Open Service-level guard (not DB enforced)

Breaking changes and migrations

Date Change Action required Reference
2026-04-13 Login now uses identifier instead of username Frontend must send identifier field
2026-04-13 Auth logic moved to service layer Internal imports updated (views → services)
2026-04-13 Invite logic moved to service layer All invite workflows must use service functions

Notes

1. Architectural milestone

The accounts app has transitioned to a service-oriented architecture:

  • Views are now thin orchestration layers
  • Business logic lives in services
  • Tests are split by layer (API vs service vs model)

This significantly improves: - maintainability - testability - scalability


2. Workforce direction

The app is evolving into a workforce management core, not just auth.

Key direction: - richer profile data (capacity, manager, travel) - scheduling + availability - skill-based assignment support

This will directly power: - planning - dispatching - reporting


3. Invite system maturity

Invite system is now production-ready:

  • lifecycle fully modeled (pending, accepted, expired, cancelled)
  • duplicate protection
  • role-based membership creation
  • async email delivery

Remaining gap: - management endpoints (list, resend, cancel)


4. Auth/session robustness

Authentication now supports:

  • multi-device sessions
  • per-device session revocation
  • full logout-all flows
  • password reset via token

Future improvement: - session expiration + cleanup - refresh token rotation enforcement


5. Testing maturity

The test suite is now:

  • layered (API / service / model)
  • comprehensive for critical flows
  • reusable via shared fixtures

This significantly reduces regression risk during further expansion.


6. Next logical expansion

Recommended next steps:

  1. Workforce availability (time-off)
  2. Invite management endpoints
  3. Audit logging (compliance + debugging)
  4. Access snapshot endpoint (/me/access)

These build directly on the current foundation without major refactors.