This commit is contained in:
@@ -5,6 +5,20 @@ surface is one CLI, `tht`; there is no separate authentication executable. The b
|
||||
opaque browser sessions and authorization, while `tht` owns protected configuration and local-user
|
||||
files.
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
BROWSER["Browser"] --> BOUNDARY["Authentication boundary"]
|
||||
BOUNDARY --> LOCAL["Local users\nArgon2id hashes"]
|
||||
BOUNDARY --> OIDC["OIDC provider\nAuthorization Code PKCE"]
|
||||
OIDC --> GROUPS["Groups claim\nexact mapping"]
|
||||
LOCAL --> PRINCIPAL["Thoth principal"]
|
||||
GROUPS --> PRINCIPAL
|
||||
PRINCIPAL --> ROLES["Roles"]
|
||||
ROLES --> PERMISSIONS["Permissions"]
|
||||
PERMISSIONS --> ROUTES["Protected routes"]
|
||||
SECRETS["Mounted secret bundle"] -.-> BOUNDARY
|
||||
```
|
||||
|
||||
## Configuration and trust boundaries
|
||||
|
||||
The installation descriptor points to an operator-controlled authentication directory. It contains
|
||||
@@ -70,8 +84,8 @@ Workspace Validate performs static authentication validation without provider co
|
||||
`tht auth check` performs live, non-interactive diagnosis: static safety plus OIDC discovery,
|
||||
issuer/JWKS, group-catalog authentication, and exact configured-group existence. Adding
|
||||
`--interactive` runs that same live diagnosis and then validates a device-flow identity when the
|
||||
provider supports Device Authorization. Workspace Test is the aggregate live workspace and
|
||||
authentication validation.
|
||||
provider supports Device Authorization. Aggregate live workspace and authentication validation is
|
||||
available through the installation diagnostics.
|
||||
|
||||
The ordered `tht doctor` report is exactly: `descriptor`, `files`, `docker`, `compose`,
|
||||
`configuration`, `authentication`, `services`, `core-http`, `frontend-http`,
|
||||
|
||||
Reference in New Issue
Block a user