import Link from "next/link"; import { eq } from "drizzle-orm"; import { auth } from "@/auth"; import { db } from "@/lib/db/client"; import { groups, userGroups } from "@/lib/db/schema"; import { Container, PageHeader } from "@/app/_components/ui/container"; import { Card } from "@/app/_components/ui/card"; import { EmptyState } from "@/app/_components/ui/empty-state"; export const dynamic = "force-dynamic"; /** * Debug page showing the OIDC groups currently associated with the signed-in * user. The list is rewritten on every sign-in from the IdP's `groups` * claim (see `lib/auth/sync-groups.ts`), so this view is effectively a * snapshot of "what your IdP told us about you at last login". * * Mainly intended as a sanity check for the upcoming sharing feature — * if the user expects to see "platform" and doesn't, the IdP probably * isn't emitting the claim, and the empty state points them at the * README troubleshooting section. */ export default async function GroupsSettingsPage() { const session = await auth(); const userId = session!.user.id; const rows = await db .select({ id: groups.id, name: groups.name, oidcIss: groups.oidcIss, syncedAt: userGroups.syncedAt, }) .from(userGroups) .innerJoin(groups, eq(userGroups.groupId, groups.id)) .where(eq(userGroups.userId, userId)) .orderBy(groups.name); return ( {rows.length === 0 ? ( ) : ( {rows.map((g, i) => (
0 ? "border-t border-border" : ""}`} >
{g.name}
synced {new Date(g.syncedAt).toLocaleString()}
{g.oidcIss}
))}
)}

Groups refresh on every sign-in. If something looks stale,{" "} sign out and sign back in.

); }