Rebuild OMSORG Connect from scratch: login-only milestone

New omsorgWeb/mitarbeiter-app/ replaces the legacy PHP app for now
with just the login flow, built fresh instead of incrementally
refactored. Reuses the already-working omsorgCore JWT auth pattern
(login, silent refresh, session-stored token pair, /api/auth/me for
role+permissions) but drops everything legacy carried alongside it:
no local MySQL user cache, no admin/user-management endpoints, no
admin UI. Employee/user management stays exclusive to OMSORG Desktop
per architecture decision - Connect only ever acts on the current
user's own session.

logout.php additionally revokes the refresh token server-side via
omsorgcore_logout(), which the legacy version never did.

Verified end-to-end against a running omsorgCore instance: login,
dashboard via /api/auth/me, logout + token revocation, unauth
redirect, and wrong-credential error handling.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Felix Kemmler
2026-08-07 14:32:55 +02:00
co-authored by Claude Sonnet 5
parent b6c1389c55
commit ee74ed65f5
11 changed files with 502 additions and 0 deletions
@@ -0,0 +1,11 @@
<?php
require_once __DIR__ . '/../lib/auth.php';
require_once __DIR__ . '/../lib/layout.php';
require_login();
layout_start('Dashboard Mitarbeiter-App');
?>
<h1 class="main-title">Willkommen, <span><?= e(current_name()) ?></span></h1>
<p class="main-sub">Eingeloggt als <?= e(current_username()) ?> (<?= e(current_role()) ?>).</p>
<?php
layout_end();