docs: converge operator guidance on tht
This commit is contained in:
@@ -16,10 +16,20 @@ than inferring a PASS.
|
||||
staged/revalidated inside that lock immediately before extraction, and checkpointing requires
|
||||
an opaque installation-bound transaction capability. Manual acceptance never substitutes for
|
||||
those automated concurrency and mutation tests.
|
||||
2. Run Workspace Validate first; it is the static authentication gate. Run `tht auth check` for
|
||||
live non-interactive diagnosis, then `tht auth check --interactive` where Device Authorization
|
||||
is available, then Workspace Test for aggregate live validation.
|
||||
3. Run `tht doctor --json` and confirm this exact report order: `descriptor`, `files`, `docker`,
|
||||
2. Set the installation and workspace identifiers, then inspect the active workspace with the
|
||||
native host CLI. This replaces the former Workspace Validate/Test wording:
|
||||
|
||||
```bash
|
||||
export THT_BIN=tht
|
||||
export INSTALLATION=/absolute/path/to/thothii-installation.yaml
|
||||
export WORKSPACE_ID=psd-clinical
|
||||
"$THT_BIN" --installation "$INSTALLATION" \
|
||||
workspace inspect --workspace "$WORKSPACE_ID" --json
|
||||
```
|
||||
|
||||
3. Run `"$THT_BIN" --installation "$INSTALLATION" auth check --json` for live non-interactive
|
||||
diagnosis, then `auth check --interactive` where Device Authorization is available.
|
||||
4. Run `"$THT_BIN" --installation "$INSTALLATION" doctor --json` and confirm this exact report order: `descriptor`, `files`, `docker`,
|
||||
`compose`, `configuration`, `authentication`, `services`, `core-http`, `frontend-http`,
|
||||
`workspace-registry`, `workflow`, `pi`.
|
||||
4. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user`
|
||||
@@ -39,6 +49,7 @@ than inferring a PASS.
|
||||
| Catalog token is wrong or lacks group-view-only access | Live check fails redacted with `oidc_group_catalog_unauthorized`. |
|
||||
| Mapped group is renamed | The next check fails closed until configuration and provider agree. |
|
||||
| Token adds an unrelated group | Login and authorization are unchanged; no warning is emitted. |
|
||||
| Authenticated PSD identity creates a known-good session | SSE connects, the session is created, and the first reviewer gate appears without unexpected `401`/`403` responses. |
|
||||
| Backend restarts with Remember me | Remembered local session survives within its TTL. |
|
||||
| Password/role/enable revision changes | Affected local sessions are rejected and reauthentication is required. |
|
||||
| CSRF or cross-origin mutation is attempted | Request is rejected. |
|
||||
|
||||
Reference in New Issue
Block a user