docs(auth): address authentication guide review
This commit is contained in:
@@ -12,7 +12,8 @@ generic OIDC; these steps configure the provider-specific group catalog only.
|
||||
in the protected bundle under `THT_AUTHENTIK_API_TOKEN`.
|
||||
4. Create or confirm the exact groups `TOT Users` and `TOT Admin`. Map them explicitly in
|
||||
`auth.yaml` to `user` and `admin`, respectively. Keep other upstream groups out of the mapping.
|
||||
5. Run the static check and then the live interactive check:
|
||||
5. Run Workspace Validate for static authentication validation. Then run live non-interactive
|
||||
diagnosis, followed by the optional device-flow identity check:
|
||||
|
||||
```sh
|
||||
tht auth check
|
||||
@@ -20,8 +21,10 @@ generic OIDC; these steps configure the provider-specific group catalog only.
|
||||
tht doctor --json
|
||||
```
|
||||
|
||||
6. Run workspace Validate and then workspace Test. Test must prove discovery/JWKS, catalog access,
|
||||
and every configured group. The diagnostic result must contain no secret values.
|
||||
6. Run Workspace Test for aggregate live workspace and authentication validation. It must prove
|
||||
discovery/JWKS, catalog access, and every configured group. The diagnostic result must contain
|
||||
no secret values. `tht doctor --json` reports `authentication` after `configuration` and before
|
||||
`services` in its exact ordered checklist.
|
||||
|
||||
Only configured exact group names are queried. Additional Authentik or directory groups are ignored
|
||||
silently, without a warning. A mapped group absent from Authentik fails closed with
|
||||
|
||||
Reference in New Issue
Block a user