Merchant Admin Foundation & Security Manual¶
Module: M00 Foundation & Access Control¶
Product: ebosAi AMP
Classification: Internal — Confidential
Version: 2.0
1. Authentication Architecture¶
Tenant administrators (admin role) and managers (manager role) access the Merchant Admin Panel via two secure pathways:
sequenceDiagram
autonumber
actor Admin as Merchant Administrator
participant Browser as Admin UI (/admin/*)
participant BFF as Backend Auth Service
participant SSO as EBOS Marketplace SSO
participant DB as Neon Database
alt Standard Path: Marketplace SSO
Admin->>Browser: Click "Sign in with EBOS SSO"
Browser->>SSO: Authenticate Admin Credentials
SSO-->>Browser: Return Marketplace JWT Token
Browser->>BFF: POST /api/v1/auth/exchange {token}
BFF->>DB: Upsert User by sso_uid & Bind tenant_id
BFF-->>Browser: Set httpOnly amp_admin_token Cookie
Browser-->>Admin: Redirect to /admin/dashboard
else Fallback Path: Emergency TempOTP
Admin->>Browser: Visit /login & Enter Work Email
Browser->>BFF: POST /api/v1/auth/tempotp/request
BFF-->>Admin: Dispatch 6-Digit Code via SMTP (10m expiry)
Admin->>Browser: Submit Code at /verify
Browser->>BFF: POST /api/v1/auth/tempotp/verify
BFF-->>Browser: Set httpOnly amp_admin_token Cookie
Browser-->>Admin: Redirect to /admin/dashboard
end
Key Security Standards:¶
- Zero Stored Passwords: No user passwords exist in the local database.
- httpOnly Cookie Protection: All administrative tokens are stored in
httpOnly,Secure,SameSite=Strictcookies, preventing client-side script inspection. - Session Timeout: Administrative sessions automatically expire after 24 hours of inactivity.
2. Multi-Tenancy Data Scoping (tenant_id)¶
All database entities across the platform are strictly isolated by tenant_id UUID foreign keys:
- The TenantContextMiddleware extracts the tenant scope directly from the authenticated JWT claims on every incoming request.
- Database service queries automatically bind WHERE tenant_id = :tenant_id.
- Zero Cross-Tenant Leakage: Administrators have absolute visibility within their own organization, but cannot access data belonging to other tenants.
3. Two-Level Tenant Security Architecture¶
The platform enforces two distinct layers of access governance:
1. Level 1 — Subscription Plan Gating: Routes and features are constrained by the company's active subscription tier (plan_1, plan_2, plan_3).
2. Level 2 — Granular User Role & Menu Overrides: Company Admins can customize individual internal user permissions and selectively enable/disable specific navigation routes.