elsa-core/specs/013-user-tasks/contracts/invitations-contract.md
Sipke Schoorstra ffff359756
feat(user-tasks): add identity-neutral workflow-bound human tasks (#7955)
Adds durable, identity-neutral, workflow-bound human tasks, and reconciles the
REST surface with the approved Studio contract.

- Flat summary/detail DTOs, a global capability descriptor, and workflow context
  captured at activation.
- Scope is part of the list authorization predicate; manager decisions require
  manage:user-tasks; a denied command answers 404 so it cannot prove a task exists.
- Guest sessions are task-scoped, action-allowlisted, and revoked when the task
  closes. Invitations resolve by token hash through the repository, wait in a
  Data Protection encrypted outbox, and are rate limited per caller.
- Masked form values are disclosed only through an audited reveal command.
- Store-specific concurrency failures are translated into a single
  UserTaskRevisionConflictException, so a concurrent edit returns the documented
  revision-conflict result behind any provider instead of a 500.

EF Core (SQLite, SQL Server, PostgreSQL, MySQL, Oracle) and VNext persistence,
hosted due/reconciliation/delivery workers, docs, and 49 tests.

Note: this branch also carries two commits inherited from its branch point that
are not part of User Tasks and are squashed in here — the revert-version
allocation change from #7917 (WorkflowDefinitionPublisher.RevertVersionAsync now
allocates from the last version rather than the latest) and an NU1903 package
pin. Merged deliberately rather than rebased out.
2026-08-25 00:09:06 +02:00

1.5 KiB

Guest Invitation Contract

Issuance and delivery

Activity definitions and authorized managers may create multiple invitations. Each invitation has a challenge provider/configuration, allowed actions, and bounded expiry (default: earlier of seven days or DueAt). Core creates an unguessable one-time secret, stores only its hash, and gives raw material once to IUserTaskInvitationDispatcher. Retry uses a protected transient outbox encrypted through ASP.NET Core Data Protection; successful or expired delivery removes the entry.

Verification

Anonymous endpoints disclose only generic invitation copy before verification, use rate limiting, and return indistinguishable failures for missing, expired, consumed, or invalid invitations. IUserTaskInvitationVerifier performs the configured challenge. Bearer-only verification is permitted only when explicitly enabled by the activity.

The first successful verification atomically:

  1. claims the still-open task for a generated guest participant;
  2. consumes the winning invitation and revokes its siblings;
  3. issues a revocable, task-scoped session through IUserTaskGuestSessionIssuer.

The guest session expires at task close or its own host-bounded TTL and grants only configured read/complete capabilities. Guests cannot release, reassign, invite, update, cancel, or manage. A manager recovers abandoned guest work by reassignment or reissue. No raw challenge response, invitation secret, or protected task data is written to audit events.