docs(auth): document local OIDC and Authentik operation
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
# Authentication manual acceptance
|
||||
|
||||
This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin
|
||||
PSD test identity supplied through the approved test-identity process. Record only sanitized
|
||||
pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal
|
||||
URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples.
|
||||
|
||||
## Preconditions and ordering
|
||||
|
||||
1. Resolve the two parked Task 13 restore preconditions before certification: acquire the lifecycle
|
||||
lock before any target-dependent preflight and stage/revalidate archive bytes and hashes inside
|
||||
that lock immediately before extraction; replace convention-only
|
||||
`createWithDependenciesLockHeld` with an opaque installation-bound transaction capability or
|
||||
closure so lock-held primitives cannot be called without the capability.
|
||||
2. Run `tht auth check`, then `tht auth check --interactive` where Device Authorization is
|
||||
available, then workspace Validate and workspace Test. Run `tht doctor --json` and confirm its
|
||||
`authentication` check precedes service and workspace checks.
|
||||
3. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user`
|
||||
and `TOT Admin → admin`. Confirm extra upstream groups are ignored without warning.
|
||||
|
||||
## Matrix
|
||||
|
||||
| Scenario | Expected result |
|
||||
|---|---|
|
||||
| Ordinary identity opens its own application/session routes | Allowed; admin-only routes return `403`. |
|
||||
| Admin identity opens admin routes | Allowed according to the `admin` permission set. |
|
||||
| Token omits `groups` | Authentication fails closed with `oidc_groups_claim_invalid`. |
|
||||
| Token has malformed, indirect, or overage groups | Authentication fails closed with `oidc_groups_claim_invalid`. |
|
||||
| Token has no mapped group | Principal has no role; protected routes return `403`; no warning is emitted. |
|
||||
| A configured group is absent from Authentik | Check fails with `oidc_mapped_group_missing`. |
|
||||
| Catalog token is wrong or lacks group-view-only access | Check fails redacted as catalog unavailable/unauthorized. |
|
||||
| Mapped group is renamed | The next check fails closed until configuration and provider agree. |
|
||||
| Token adds an unrelated group | Login and authorization are unchanged; no warning is emitted. |
|
||||
| Backend restarts with Remember me | Remembered local session survives within its TTL. |
|
||||
| Password/role/enable revision changes | Affected local sessions are rejected and reauthentication is required. |
|
||||
| CSRF or cross-origin mutation is attempted | Request is rejected. |
|
||||
| Logout | Cookie expires and the server session is deleted. |
|
||||
| Provider outage | Live check and OIDC login fail closed; no credential is exposed. |
|
||||
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
|
||||
|
||||
## Status at Task 14
|
||||
|
||||
Documentation and deterministic contract checks are the Task 14 scope. Browser OIDC callback E2E,
|
||||
native Windows behavioral execution, the two parked restore-lock preconditions above, PSD/manual
|
||||
identities, and any external L2 execution remain pending Task 15/release gates. Do not mark this
|
||||
matrix PASS until those gates have actual retained evidence.
|
||||
Reference in New Issue
Block a user