Skip to content

ImpersonationBanner

<caos-impersonation-banner>

the persistent strip saying you are signed in as somebody else

May be placed on a seam in the workspace frame.

Name Attribute Description Type Default Required
targetLabel target-label, markup only The user being viewed as, drawn in bold in the middle of the strip. Its PRESENCE is what makes the strip visible: with it unset or empty the element hides itself and renders nothing. text none declared Required
realLabel real-label, markup only The administrator’s own name, drawn as a lighter “signed in as …” tail. Unset, the tail is not drawn. Worth setting on a shared machine, where “who am I really” is the question the strip is there to answer. text none declared Optional
product product, markup only The platform name in the copy — “Viewing as …”. text the app Optional
expiresAt expires-at, markup only When the borrowed session runs out, as an ISO timestamp. Set it and the strip carries a countdown beside the exit, coarse (minutes, rounded up) until the last minute and then seconds. Unset, unparseable, or already past, and no countdown is drawn at all — a wrong number here is worse than none, because somebody plans around it. text none declared Optional
Name When it fires What it carries
impersonation-end The “End Login As” control is pressed. It bubbles and crosses the shadow boundary so the shell can listen at its root. The strip does NOT hide itself or undo anything — the host ends the override and then clears target-label, so the strip stays up until the session is genuinely back to the real user. nothing

Nothing goes inside this piece.

Design token What it controls
--caos-color-accent The fill of the whole strip — the one thing about it a tenant’s brand moves.
--caos-font-mono The typeface of the message and the exit control.
--caos-radius-sm The corners of the exit control.
--caos-color-accent-contrast The lettering, the hairline under the bar, and the exit control’s border and focus ring. White by default; a brand with a pale accent sets a darker ink here.

Nothing else drives this piece by calling it.

Nothing on this piece can be read back.

Part Which piece of it When it is there
::part(banner) the banner strip Always
::part(remaining) the time left before the borrowed session runs out Always
::part(exit) the control that ends the borrowed session Always

Whenever a session is running as somebody other than the person signed in — support impersonation, an administrator reproducing a report, a role check. It is the strip that stops that state from being invisible.

  • NoticeBanner — The message is about the PAGE rather than the session — a condition of this surface, a decision to make here. A notice banner belongs inside the page and scrolls with it; this strip belongs to the frame and must not.
  • Topbar — What is wanted is the control that STARTS the switch, and the account menu that offers it. That is the top bar’s job; this strip is what the switch leaves behind.
  • StatusPill — The environment or mode needs marking somewhere quiet rather than announcing across the top of the screen — the dev pill is for that.

The strip is a polite live region (role="status", aria-live="polite"), so it is announced when it appears without cutting across whatever is being read, and it is genuinely removed from the accessibility tree when there is no target rather than being drawn empty. The exit is a real button with a visible text label — not an icon alone — and carries its own light focus ring, because the ordinary accent ring would be invisible against the accent fill. Left to the author: binding impersonation-end (an exit control that does nothing is worse here than no strip at all), and keeping the strip outside any container that scrolls or clips.

The strip as the shell draws it: who is being viewed as, who is really signed in, and the exit that is reachable from every page.

{
"id": "example",
"section": "A session running as somebody else",
"columns": 1,
"items": [
{
"id": "impersonation_banner_1",
"type": "component",
"key": "impersonation_banner",
"inputs": {
"target_label": "Marcus Reed",
"real_label": "Dana Whitfield",
"product": "Cloud Atlantis OS"
}
}
]
}
<caos-impersonation-banner target-label="Marcus Reed" real-label="Dana Whitfield" product="Cloud Atlantis OS"></caos-impersonation-banner>

Only the user being viewed as: the copy falls back to “the app” and the “signed in as” tail is not drawn — which is the version to avoid on a shared machine, where the missing half is the half that says who you really are.

{
"id": "example",
"section": "The least it can be told",
"columns": 1,
"items": [
{
"id": "impersonation_banner_1",
"type": "component",
"key": "impersonation_banner",
"inputs": {
"target_label": "Marcus Reed"
}
}
]
}
<caos-impersonation-banner target-label="Marcus Reed"></caos-impersonation-banner>