docs(auth): document runtime projection operations
This commit is contained in:
@@ -35,6 +35,13 @@ than inferring a PASS.
|
||||
4. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user`
|
||||
and `TOT Admin → admin`. Confirm extra upstream groups are ignored without warning.
|
||||
|
||||
5. For a projected Linux server, before any start gate, collect only the redacted result of
|
||||
`sudo tht --installation "$INSTALLATION" auth status --json`. Record `state`, generation,
|
||||
canonical revision, and `equal`; do not retain authentication YAML, user records, hashes, or
|
||||
environment output. `ready` plus `equal: true` is required. A blocked or unequal result is a
|
||||
fail-closed condition: do not start, and use `sudo tht --installation "$INSTALLATION" auth
|
||||
publish` followed by the same status command only after the canonical root is available.
|
||||
|
||||
## Matrix
|
||||
|
||||
| Scenario | Expected result |
|
||||
@@ -56,6 +63,7 @@ than inferring a PASS.
|
||||
| Logout | Cookie expires and the server session is deleted. |
|
||||
| Provider outage | Live check reports `oidc_discovery_unreachable`; browser login fails closed without exposing credentials. |
|
||||
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
|
||||
| Projected authentication restore | Candidate generation and any recovery generation are published from the canonical root; a failed verification remains blocked and start is refused. |
|
||||
|
||||
## Status at Task 15
|
||||
|
||||
|
||||
Reference in New Issue
Block a user