Accounts App — Change Log¶
This log tracks software changes for this area.
Current status¶
| Item | Status | Notes |
|---|---|---|
| Active development | Open | Workforce enrichment + service layer completed |
| Next release target | TBA | Stabilization + workforce extensions |
| Known risk | Medium | Auth/session + invite lifecycle critical paths |
Recent changes (newest first)¶
| Date | Type | Summary | Impact | Reference |
|---|---|---|---|---|
| 2026-04-13 | Refactor | Moved auth business logic to service layer (services/auth.py) |
Medium | N/A |
| 2026-04-13 | Refactor | Moved invite lifecycle logic to service layer (services/invite.py) |
Medium | N/A |
| 2026-04-13 | Feature | Added identifier-based login (username OR email) | Low | N/A |
| 2026-04-13 | Feature | Implemented full device + session lifecycle (logout, revoke, logout-all) | Medium | N/A |
| 2026-04-13 | Feature | Added invite lifecycle: create, preview, accept, resend, cancel | High | N/A |
| 2026-04-13 | Feature | Added workforce profile enrichment (manager, travel, capacity fields) | Medium | N/A |
| 2026-04-13 | Refactor | Standardized serializers into domain folders (serializers/auth, devices, etc.) |
Low | N/A |
| 2026-04-13 | Refactor | Reorganized views into domain-based modules (views/auth, views/invites, etc.) |
Low | N/A |
| 2026-04-13 | Feature | Added structured test layers (API vs services vs models) | Medium | N/A |
| 2026-04-13 | Feature | Added MkDocs documentation (models, serializers, services, views, tasks, urls, tests) | Low | N/A |
Open items and status¶
| ID | Title | Status | Priority | Owner | Target | Reference |
|---|---|---|---|---|---|---|
| ACCOUNTS-001 | Add workforce availability (time-off / absences) model | Open | P1 | Unassigned | TBA | |
| ACCOUNTS-002 | Add workforce certifications with expiry alerts | Open | P1 | Unassigned | TBA | |
| ACCOUNTS-003 | Add manager hierarchy endpoints (team tree / reporting lines) | Open | P2 | Unassigned | TBA | |
| ACCOUNTS-004 | Add invite management endpoints (list/resend/cancel via API) | Open | P1 | Unassigned | TBA | |
| ACCOUNTS-005 | Add device/session cleanup job (expired sessions) | Open | P2 | Unassigned | TBA | |
| ACCOUNTS-006 | Add audit logging for auth + invite actions | Open | P1 | Unassigned | TBA | |
| ACCOUNTS-007 | Add rate limit config defaults for all throttled views | Open | P2 | Unassigned | TBA | |
| ACCOUNTS-008 | Add me/access endpoint (effective permissions snapshot) |
Open | P2 | Unassigned | TBA | |
| ACCOUNTS-009 | Improve skill model with tagging / hierarchy | Open | P3 | Unassigned | TBA | |
| ACCOUNTS-010 | Add soft-delete or deactivation strategy for users | Open | P2 | Unassigned | TBA |
Known bugs¶
| ID | Symptom | Severity | Status | Workaround | Reference |
|---|---|---|---|---|---|
| BUG-ACCOUNTS-001 | Missing DRF throttle rates causes runtime errors in tests | Low | Mitigated | Monkeypatch throttles in tests | |
| BUG-ACCOUNTS-002 | DeviceSession not auto-cleaned for expired refresh tokens | Medium | Open | Manual logout-all | |
| BUG-ACCOUNTS-003 | Invite duplicate detection edge case with race conditions | Medium | Open | Service-level guard (not DB enforced) |
Breaking changes and migrations¶
| Date | Change | Action required | Reference |
|---|---|---|---|
| 2026-04-13 | Login now uses identifier instead of username |
Frontend must send identifier field |
|
| 2026-04-13 | Auth logic moved to service layer | Internal imports updated (views → services) | |
| 2026-04-13 | Invite logic moved to service layer | All invite workflows must use service functions |
Notes¶
1. Architectural milestone¶
The accounts app has transitioned to a service-oriented architecture:
- Views are now thin orchestration layers
- Business logic lives in services
- Tests are split by layer (API vs service vs model)
This significantly improves: - maintainability - testability - scalability
2. Workforce direction¶
The app is evolving into a workforce management core, not just auth.
Key direction: - richer profile data (capacity, manager, travel) - scheduling + availability - skill-based assignment support
This will directly power: - planning - dispatching - reporting
3. Invite system maturity¶
Invite system is now production-ready:
- lifecycle fully modeled (pending, accepted, expired, cancelled)
- duplicate protection
- role-based membership creation
- async email delivery
Remaining gap: - management endpoints (list, resend, cancel)
4. Auth/session robustness¶
Authentication now supports:
- multi-device sessions
- per-device session revocation
- full logout-all flows
- password reset via token
Future improvement: - session expiration + cleanup - refresh token rotation enforcement
5. Testing maturity¶
The test suite is now:
- layered (API / service / model)
- comprehensive for critical flows
- reusable via shared fixtures
This significantly reduces regression risk during further expansion.
6. Next logical expansion¶
Recommended next steps:
- Workforce availability (time-off)
- Invite management endpoints
- Audit logging (compliance + debugging)
- Access snapshot endpoint (
/me/access)
These build directly on the current foundation without major refactors.