Staff given a post in Smart Office and another in freight only ever
loaded one of them. Two causes, both in how the IAM guard collapses the
login snapshot:
- `x-current-position-id` is read two ways inside one function: the
employee row is matched on `position.id`, the position on
`employeePositionId`. Freight sends the latter, Smart Office the
former, so whichever value arrives one lookup matches nothing and
falls back to `positions[0]`. FreightJwtGuard now matches both fields.
- IAM keeps one employee row per organization, and EDR and EDR Freight
are separate organizations, so a user holding a post in each owns two
rows. Only the active row reached `collectPermissionKeys`, so the
freight post's permissions disappeared whenever the other row won the
active slot. `employee.positions` now unions every row, which is what
the util already does for the array shape.
`delegatedPositions` stays scoped to the active row on purpose: yard
scope widens on it, and someone standing in on another organization's
row is not this desk's stand-in.
/auth/me now returns every employee row, active row first, so the
position picker can offer a desk that is not on the active row.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
IAM lets an employee hold several positions, but the vendored JwtGuard
collapses employee.positions[] down to a single employee.position and
drops the rest. Non-delegate secondary positions vanished entirely, so
staff on two posts resolved to one post's permissions and every check
on the other rejected them.
FreightJwtGuard re-attaches the full list from the same session
snapshot the parent guard already read, so nothing extra is fetched
per request beyond a cached session lookup. employee.position is left
untouched, keeping audit logging and delegation unaffected.
collectPermissionKeys and collectPositionTypeKeys now union across
every position, and /me returns them all.
Verified against a real two-position user (djibouti-gl-director +
djibouti-gl-chief) on the local dev database:
/me positions 1 -> 2
/me permissionKeys 17 -> 28
GET /api/interchange-documents 403 -> 200
GET /api/trains 403 -> 200
11 permissions recovered, none lost. Six single-position users return
byte-identical payloads before and after.