Adds durable, identity-neutral, workflow-bound human tasks, and reconciles the REST surface with the approved Studio contract. - Flat summary/detail DTOs, a global capability descriptor, and workflow context captured at activation. - Scope is part of the list authorization predicate; manager decisions require manage:user-tasks; a denied command answers 404 so it cannot prove a task exists. - Guest sessions are task-scoped, action-allowlisted, and revoked when the task closes. Invitations resolve by token hash through the repository, wait in a Data Protection encrypted outbox, and are rate limited per caller. - Masked form values are disclosed only through an audited reveal command. - Store-specific concurrency failures are translated into a single UserTaskRevisionConflictException, so a concurrent edit returns the documented revision-conflict result behind any provider instead of a 500. EF Core (SQLite, SQL Server, PostgreSQL, MySQL, Oracle) and VNext persistence, hosted due/reconciliation/delivery workers, docs, and 49 tests. Note: this branch also carries two commits inherited from its branch point that are not part of User Tasks and are squashed in here — the revert-version allocation change from #7917 (WorkflowDefinitionPublisher.RevertVersionAsync now allocates from the last version rather than the latest) and an NU1903 package pin. Merged deliberately rather than rebased out.
3 KiB
3 KiB
Architecture Decision Records
- 1. Record architecture decisions
- 2. Fault Propagation from Child to Parent Activities
- 3. Direct Bookmark Management in WorkflowExecutionContext
- 4. Activity Execution Snapshots
- 5. Token-Centric Flowchart Execution Model
- 6. Tenant Deleted Event
- 7. Adoption of Explicit Merge Modes for Flowchart Joins
- 8. Empty String as Default Tenant ID
- 9. Asterisk Sentinel Value for Tenant-Agnostic Entities
- 10. Default Admin User Bootstrap for Initial Identity Access
- 11. Output Conversion Occurs Synchronously at the Binding Boundary
- 12. Output Converters Use Explicit Stable Identities
- 13. Output Converter Discovery Is Server-Owned
- 14. Broker external sign-in through Elsa Server
- 15. Compose a scoped connection registry
- 16. Extend authentication through deployed descriptor providers
- 17. Separate external identity from Elsa authorization
- 18. Separate provider trust from broker invariants
- 19. Bind sessions to shared state and connection revisions
- 20. Publish audit-ready security notifications
- 21. Identify host connections by logical key and use explicit overrides
- 22. Match unlinked identities with trusted user matchers
- 23. Separate authentication UI composition from security administration
- 24. Use exact OIDC discovery and deployment-derived callbacks
- 25. Two-axis authorization model with open resources and open verbs
- 26. Use Identity-Neutral Participant References for User Tasks
- 27. Project User Tasks from Committed Workflow Bookmarks