docs(auth): document local OIDC and Authentik operation

This commit is contained in:
2026-08-18 03:07:33 +02:00
parent 6ec5b76c54
commit f4f38717e1
17 changed files with 407 additions and 0 deletions
+14
View File
@@ -10,6 +10,20 @@
Last updated: 2026-08-13 (P2–P6 accepted; P7 live preprocessing PASS on PSD).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
### Task 14 authentication documentation — implementation status (2026-08-18)
- Documentation now describes local Argon2id users, ordinary and remembered session expiry,
revision invalidation, generic OIDC direct groups claims, exact group-role mapping, Authentik
group-view-only catalog checks, tht auth/tht doctor ordering, diagnostics, CSRF, and restore
reauthentication.
- Task 14 documentation smoke and strict documentation build are release evidence for the docs
scope only. Browser OIDC callback E2E, native Windows behavioral execution, PSD/manual test
identities, and external L2 remain pending Task 15/release gates.
- Task 13 has two parked restore-lock preconditions that remain mandatory before certification:
lock before target-dependent preflight with archive bytes/hashes staged and revalidated inside the
lock immediately before extraction; and an opaque installation-bound transaction capability or
closure replacing convention-only lock-held helpers.
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)
- **Scope:** P3 (PRD D3): a versioned shared canonicalizer produces the non-secret effective