test(auth): gate local and OIDC authentication release

This commit is contained in:
2026-08-18 06:02:25 +02:00
parent 7cf7d9db6b
commit 8a3fa5031d
23 changed files with 1711 additions and 168 deletions
+25 -17
View File
@@ -7,26 +7,34 @@
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
> Last updated: 2026-08-18 (Task 14 documentation implemented; strict documentation and
> authentication release gates remain blocking or pending as listed below).
> Last updated: 2026-08-18 (Task 15 automated evidence recorded; the authentication feature is
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 14 authentication documentation — implementation status (2026-08-18)
### Task 15 authentication release — automated evidence, release incomplete (2026-08-18)
- Documentation now describes local Argon2id users, ordinary and remembered session expiry,
revision invalidation, generic OIDC direct groups claims, exact group-role mapping, Authentik
group-view-only catalog checks, tht auth/tht doctor ordering, diagnostics, CSRF, and restore
reauthentication.
- The Task 14 authentication-documentation smoke passes. The MkDocs `--strict` baseline remains a
blocking release gate: it exits 1 with 69 warnings, the same warning count before and after Task
14. It is not a PASS or release evidence.
- Browser OIDC callback E2E, native Windows behavioral execution, PSD/manual test identities, and
external L2 remain pending Task 15/release gates. Task 14 documentation is implemented, not
release-accepted.
- Task 13 has two parked restore-lock preconditions that remain mandatory before certification:
lock before target-dependent preflight with archive bytes/hashes staged and revalidated inside the
lock immediately before extraction; and an opaque installation-bound transaction capability or
closure replacing convention-only lock-held helpers.
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
target-dependent preflight, stages/revalidates archive bytes and hashes under that lock, and uses
an opaque installation-bound transaction capability. Focused mutation/concurrency/lock-leak
tests and the full Go race/build gate pass.
- PASS on the pinned Node `v24.16.0`: backend 75 files / 1081 tests plus typecheck/build; frontend
61 files / 444 tests plus typecheck/build and 6 Playwright tests; hermetic loopback OIDC browser
smoke; harness 921 passed / 4 L2 deselected; authentication-documentation smoke; unified Docker
smoke with scoped cleanup; installer shell test; relevant Compose/security contracts. The default
host Node is `v25.6.1`; it is not the release contract and no tracked `v24.19.0` pin exists.
- Task15 fixture regressions in preprocess, server Pi-state, and Pi-auth Compose contracts were
repaired and their focused checks pass. Static Windows amd64 cross-build and test compilation
pass for 18 Go packages.
- FAIL baseline evidence: Ruff reports 192 errors; MkDocs `--strict` exits 1 with 69 warnings;
the canonical-install and workspace-install-doc checks report existing manual wording mismatches;
the Pi user-auth Compose check reaches an existing model allow-list mismatch; and the broad
deployment-coupling scanner sees preserved ignored private deployment material.
- PENDING evidence: native Windows execution (no KVM, `sshpass`, Windows container, or PowerShell);
real PSD/manual acceptance (no real test identity/access); L2 (no configured local secret layout);
and isolated provider-readiness Docker smoke (a host port is already occupied by an unrelated
resource). These are not PASS claims.
- **Release state: NOT COMPLETE.** Do not mark authentication release-complete until every required
gate is rerun in an eligible environment and is PASS.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)