docs(auth): document local OIDC and Authentik operation
This commit is contained in:
@@ -10,6 +10,20 @@
|
||||
Last updated: 2026-08-13 (P2–P6 accepted; P7 live preprocessing PASS on PSD).
|
||||
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
|
||||
|
||||
### Task 14 authentication documentation — implementation status (2026-08-18)
|
||||
|
||||
- Documentation now describes local Argon2id users, ordinary and remembered session expiry,
|
||||
revision invalidation, generic OIDC direct groups claims, exact group-role mapping, Authentik
|
||||
group-view-only catalog checks, tht auth/tht doctor ordering, diagnostics, CSRF, and restore
|
||||
reauthentication.
|
||||
- Task 14 documentation smoke and strict documentation build are release evidence for the docs
|
||||
scope only. Browser OIDC callback E2E, native Windows behavioral execution, PSD/manual test
|
||||
identities, and external L2 remain pending Task 15/release gates.
|
||||
- Task 13 has two parked restore-lock preconditions that remain mandatory before certification:
|
||||
lock before target-dependent preflight with archive bytes/hashes staged and revalidated inside the
|
||||
lock immediately before extraction; and an opaque installation-bound transaction capability or
|
||||
closure replacing convention-only lock-held helpers.
|
||||
|
||||
### P3 effective configuration and `.tht-dwh` — implementation complete, automated PASS, manual PASS (2026-08-13)
|
||||
|
||||
- **Scope:** P3 (PRD D3): a versioned shared canonicalizer produces the non-secret effective
|
||||
|
||||
Reference in New Issue
Block a user