docs(auth): document runtime projection operations
This commit is contained in:
@@ -35,6 +35,13 @@ than inferring a PASS.
|
||||
4. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user`
|
||||
and `TOT Admin → admin`. Confirm extra upstream groups are ignored without warning.
|
||||
|
||||
5. For a projected Linux server, before any start gate, collect only the redacted result of
|
||||
`sudo tht --installation "$INSTALLATION" auth status --json`. Record `state`, generation,
|
||||
canonical revision, and `equal`; do not retain authentication YAML, user records, hashes, or
|
||||
environment output. `ready` plus `equal: true` is required. A blocked or unequal result is a
|
||||
fail-closed condition: do not start, and use `sudo tht --installation "$INSTALLATION" auth
|
||||
publish` followed by the same status command only after the canonical root is available.
|
||||
|
||||
## Matrix
|
||||
|
||||
| Scenario | Expected result |
|
||||
@@ -56,6 +63,7 @@ than inferring a PASS.
|
||||
| Logout | Cookie expires and the server session is deleted. |
|
||||
| Provider outage | Live check reports `oidc_discovery_unreachable`; browser login fails closed without exposing credentials. |
|
||||
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
|
||||
| Projected authentication restore | Candidate generation and any recovery generation are published from the canonical root; a failed verification remains blocked and start is refused. |
|
||||
|
||||
## Status at Task 15
|
||||
|
||||
|
||||
@@ -29,6 +29,13 @@ verdi installazione, workspace, DWH, Qdrant, Ollama e preprocessing.
|
||||
|
||||
## 1. Stato generale
|
||||
|
||||
Prima del gate manuale di avvio, per una descriptor server con runtime projection eseguire solo il
|
||||
controllo redatto `sudo tht --installation "$INSTALLATION" auth status --json`. Il risultato deve
|
||||
dire `ready` ed `equal: true`. Se è `blocked`, mancante o diverso dal canonical root, non avviare:
|
||||
Sol può eseguire `sudo tht --installation "$INSTALLATION" auth publish` e ripetere il controllo,
|
||||
senza copiare YAML, hash, password, token o environment nel rapporto. Questo documento non
|
||||
autorizza l'avvio; Project A resta soggetto a un'esplicita autorizzazione separata.
|
||||
|
||||
Eseguire:
|
||||
|
||||
```bash
|
||||
|
||||
Reference in New Issue
Block a user