test(auth): gate local and OIDC authentication release
This commit is contained in:
+25
-17
@@ -7,26 +7,34 @@
|
||||
> ThothII per il repository (app + CLI `thothctl`), (3) come usare l'applicazione ThothII di base
|
||||
> (sessioni, domande, gate). Il documento userà parole semplici ed esempi; i dettagli tecnici
|
||||
> resteranno nei contratti esistenti. Esempio pratico completo: Policlinico San Donato.
|
||||
> Last updated: 2026-08-18 (Task 14 documentation implemented; strict documentation and
|
||||
> authentication release gates remain blocking or pending as listed below).
|
||||
> Last updated: 2026-08-18 (Task 15 automated evidence recorded; the authentication feature is
|
||||
> not complete or release-accepted while the required FAIL/PENDING gates listed below remain).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### Task 14 authentication documentation — implementation status (2026-08-18)
|
||||
### Task 15 authentication release — automated evidence, release incomplete (2026-08-18)
|
||||
|
||||
- Documentation now describes local Argon2id users, ordinary and remembered session expiry,
|
||||
revision invalidation, generic OIDC direct groups claims, exact group-role mapping, Authentik
|
||||
group-view-only catalog checks, tht auth/tht doctor ordering, diagnostics, CSRF, and restore
|
||||
reauthentication.
|
||||
- The Task 14 authentication-documentation smoke passes. The MkDocs `--strict` baseline remains a
|
||||
blocking release gate: it exits 1 with 69 warnings, the same warning count before and after Task
|
||||
14. It is not a PASS or release evidence.
|
||||
- Browser OIDC callback E2E, native Windows behavioral execution, PSD/manual test identities, and
|
||||
external L2 remain pending Task 15/release gates. Task 14 documentation is implemented, not
|
||||
release-accepted.
|
||||
- Task 13 has two parked restore-lock preconditions that remain mandatory before certification:
|
||||
lock before target-dependent preflight with archive bytes/hashes staged and revalidated inside the
|
||||
lock immediately before extraction; and an opaque installation-bound transaction capability or
|
||||
closure replacing convention-only lock-held helpers.
|
||||
- Task 13 carry-ins are closed with focused TDD: restore acquires the lifecycle lock before
|
||||
target-dependent preflight, stages/revalidates archive bytes and hashes under that lock, and uses
|
||||
an opaque installation-bound transaction capability. Focused mutation/concurrency/lock-leak
|
||||
tests and the full Go race/build gate pass.
|
||||
- PASS on the pinned Node `v24.16.0`: backend 75 files / 1081 tests plus typecheck/build; frontend
|
||||
61 files / 444 tests plus typecheck/build and 6 Playwright tests; hermetic loopback OIDC browser
|
||||
smoke; harness 921 passed / 4 L2 deselected; authentication-documentation smoke; unified Docker
|
||||
smoke with scoped cleanup; installer shell test; relevant Compose/security contracts. The default
|
||||
host Node is `v25.6.1`; it is not the release contract and no tracked `v24.19.0` pin exists.
|
||||
- Task15 fixture regressions in preprocess, server Pi-state, and Pi-auth Compose contracts were
|
||||
repaired and their focused checks pass. Static Windows amd64 cross-build and test compilation
|
||||
pass for 18 Go packages.
|
||||
- FAIL baseline evidence: Ruff reports 192 errors; MkDocs `--strict` exits 1 with 69 warnings;
|
||||
the canonical-install and workspace-install-doc checks report existing manual wording mismatches;
|
||||
the Pi user-auth Compose check reaches an existing model allow-list mismatch; and the broad
|
||||
deployment-coupling scanner sees preserved ignored private deployment material.
|
||||
- PENDING evidence: native Windows execution (no KVM, `sshpass`, Windows container, or PowerShell);
|
||||
real PSD/manual acceptance (no real test identity/access); L2 (no configured local secret layout);
|
||||
and isolated provider-readiness Docker smoke (a host port is already occupied by an unrelated
|
||||
resource). These are not PASS claims.
|
||||
- **Release state: NOT COMPLETE.** Do not mark authentication release-complete until every required
|
||||
gate is rerun in an eligible environment and is PASS.
|
||||
|
||||
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user