Adds durable, identity-neutral, workflow-bound human tasks, and reconciles the REST surface with the approved Studio contract. - Flat summary/detail DTOs, a global capability descriptor, and workflow context captured at activation. - Scope is part of the list authorization predicate; manager decisions require manage:user-tasks; a denied command answers 404 so it cannot prove a task exists. - Guest sessions are task-scoped, action-allowlisted, and revoked when the task closes. Invitations resolve by token hash through the repository, wait in a Data Protection encrypted outbox, and are rate limited per caller. - Masked form values are disclosed only through an audited reveal command. - Store-specific concurrency failures are translated into a single UserTaskRevisionConflictException, so a concurrent edit returns the documented revision-conflict result behind any provider instead of a 500. EF Core (SQLite, SQL Server, PostgreSQL, MySQL, Oracle) and VNext persistence, hosted due/reconciliation/delivery workers, docs, and 49 tests. Note: this branch also carries two commits inherited from its branch point that are not part of User Tasks and are squashed in here — the revert-version allocation change from #7917 (WorkflowDefinitionPublisher.RevertVersionAsync now allocates from the last version rather than the latest) and an NU1903 package pin. Merged deliberately rather than rebased out.
1.5 KiB
Guest Invitation Contract
Issuance and delivery
Activity definitions and authorized managers may create multiple invitations. Each invitation has a challenge provider/configuration, allowed actions, and bounded expiry (default: earlier of seven days or DueAt). Core creates an unguessable one-time secret, stores only its hash, and gives raw material once to IUserTaskInvitationDispatcher. Retry uses a protected transient outbox encrypted through ASP.NET Core Data Protection; successful or expired delivery removes the entry.
Verification
Anonymous endpoints disclose only generic invitation copy before verification, use rate limiting, and return indistinguishable failures for missing, expired, consumed, or invalid invitations. IUserTaskInvitationVerifier performs the configured challenge. Bearer-only verification is permitted only when explicitly enabled by the activity.
The first successful verification atomically:
- claims the still-open task for a generated guest participant;
- consumes the winning invitation and revokes its siblings;
- issues a revocable, task-scoped session through
IUserTaskGuestSessionIssuer.
The guest session expires at task close or its own host-bounded TTL and grants only configured read/complete capabilities. Guests cannot release, reassign, invite, update, cancel, or manage. A manager recovers abandoned guest work by reassignment or reissue. No raw challenge response, invitation secret, or protected task data is written to audit events.