test(auth): gate local and OIDC authentication release
This commit is contained in:
@@ -4,14 +4,18 @@ This is a release-gate checklist, not evidence. Use one ordinary PSD test identi
|
||||
PSD test identity supplied through the approved test-identity process. Record only sanitized
|
||||
pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal
|
||||
URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples.
|
||||
Keep the retained result under `.artifacts/manual-acceptance/authentication/<run-id>/` with a
|
||||
sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or
|
||||
unbounded logs. If the approved identities or access are unavailable, record **PENDING** rather
|
||||
than inferring a PASS.
|
||||
|
||||
## Preconditions and ordering
|
||||
|
||||
1. Resolve the two parked Task 13 restore preconditions before certification: acquire the lifecycle
|
||||
lock before any target-dependent preflight and stage/revalidate archive bytes and hashes inside
|
||||
that lock immediately before extraction; replace convention-only
|
||||
`createWithDependenciesLockHeld` with an opaque installation-bound transaction capability or
|
||||
closure so lock-held primitives cannot be called without the capability.
|
||||
1. Confirm retained Task 13 evidence for the restore prerequisites before certification: the
|
||||
lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are
|
||||
staged/revalidated inside that lock immediately before extraction, and checkpointing requires
|
||||
an opaque installation-bound transaction capability. Manual acceptance never substitutes for
|
||||
those automated concurrency and mutation tests.
|
||||
2. Run Workspace Validate first; it is the static authentication gate. Run `tht auth check` for
|
||||
live non-interactive diagnosis, then `tht auth check --interactive` where Device Authorization
|
||||
is available, then Workspace Test for aggregate live validation.
|
||||
@@ -42,9 +46,13 @@ URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic s
|
||||
| Provider outage | Live check reports `oidc_discovery_unreachable`; browser login fails closed without exposing credentials. |
|
||||
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
|
||||
|
||||
## Status at Task 14
|
||||
## Status at Task 15
|
||||
|
||||
Documentation and deterministic contract checks are the Task 14 scope. Browser OIDC callback E2E,
|
||||
native Windows behavioral execution, the two parked restore-lock preconditions above, PSD/manual
|
||||
identities, and any external L2 execution remain pending Task 15/release gates. Do not mark this
|
||||
matrix PASS until those gates have actual retained evidence.
|
||||
The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list
|
||||
surface and the complete OIDC Authorization Code + PKCE callback, including direct `groups`
|
||||
fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator
|
||||
flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance.
|
||||
|
||||
Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive
|
||||
device acceptance, and external L2 remain **PENDING** until actual retained evidence exists. Do
|
||||
not mark the feature or this matrix release-complete while any required gate remains pending.
|
||||
|
||||
Reference in New Issue
Block a user