Codex
82e2c91f42
feat: implement memory and evidence administration with guided repairs
...
Publish documentation / publish (push) Successful in 1m27s
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.
Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
2026-09-10 10:31:34 +02:00
Codex
f586152636
fix: close catalog review gaps
Publish documentation / publish (push) Successful in 38s
2026-08-31 16:28:42 +02:00
Codex
79c4c925b5
feat: implement metadata catalog database management
2026-08-27 22:43:54 +02:00
marcopan
8b524b4314
fix(auth): expose raw projected config revision
2026-08-26 02:58:33 +02:00
User
abd68470da
fix(auth): expose trusted upstream mode
2026-08-22 16:29:30 +02:00
User
cc72e65f9d
fix(workspaces): align postgres connection diagnostics
2026-08-22 13:49:21 +02:00
User
1e2c4e65c5
fix(auth): close CURRENT publication race
2026-08-21 22:51:38 +02:00
User
da2f4a6681
fix(auth): harden runtime projection validation
2026-08-21 22:46:42 +02:00
User
05f8615887
feat(auth): load immutable runtime projection snapshots
2026-08-21 22:31:38 +02:00
marcopan
d43738eeae
fix(auth): require local registry ownership
2026-08-18 10:31:44 +02:00
marcopan
e8b9995ed0
feat(auth): integrate authentication with installation lifecycle
2026-08-17 23:33:51 +02:00
marcopan
7e52df2702
fix(auth): address Task 13 deployment review findings
2026-08-17 21:31:25 +02:00
marcopan
ef244ab56d
fix(auth): harden unified diagnostic execution
2026-08-17 17:25:26 +02:00
marcopan
30ee9433dc
fix(auth): harden unified diagnostic execution
2026-08-17 16:39:54 +02:00
marcopan
3ed00ff086
feat(auth): include authentication in workspace and tht diagnostics
2026-08-17 15:51:16 +02:00
marcopan
cb0e873ed7
fix(auth): pin native auth storage operations
2026-08-17 14:52:21 +02:00
marcopan
6d438f4c7e
fix(auth): close diagnostic filesystem races
2026-08-17 13:04:15 +02:00
marcopan
be1724890a
fix(auth): make diagnostics bounded and portable
2026-08-17 12:19:19 +02:00
marcopan
7cfbee36fa
fix(auth): make diagnostics match runtime safety
2026-08-17 11:23:52 +02:00
marcopan
f0ae680671
feat(auth): validate mapped groups through Authentik
2026-08-17 10:44:56 +02:00
marcopan
33ae7cfdc2
fix(auth): bound all OIDC provider exchanges
2026-08-17 10:03:07 +02:00
marcopan
c86f01e886
fix(auth): paginate session maintenance safely
2026-08-17 09:05:20 +02:00
marcopan
3e7bb11313
fix(auth): isolate bounded OIDC cleanup
2026-08-17 07:46:43 +02:00
marcopan
bdabecbb63
fix(auth): bound OIDC initiation and transport
2026-08-17 07:03:19 +02:00
marcopan
8573500121
fix(auth): harden OIDC browser transactions
2026-08-17 06:18:49 +02:00
marcopan
4fe51cbeb1
feat(auth): add generic OIDC login with mandatory groups
2026-08-17 05:44:10 +02:00
marcopan
8c67cb75dc
fix(auth): honor HTTPS sessions in Pi management
2026-08-17 01:46:34 +02:00
marcopan
09e546c1ef
fix(auth): bind request auth snapshots
2026-08-17 01:11:25 +02:00
marcopan
94c2cd3709
fix(auth): bind current local registry and CORS
2026-08-17 00:34:58 +02:00
marcopan
c34e01e9b9
fix(auth): harden async login boundaries
2026-08-17 00:00:34 +02:00
marcopan
29bfb41363
feat(auth): add local login and CSRF-protected sessions
2026-08-16 23:23:55 +02:00
marcopan
8477a69a29
fix(auth): tighten bridge claim protocol
2026-08-16 22:44:44 +02:00
marcopan
7d9ca13f1d
fix(auth): harden Windows storage bridge
2026-08-16 22:16:13 +02:00
marcopan
c9b02fc57e
fix(auth): add Windows session storage bridge
2026-08-16 21:43:03 +02:00
marcopan
6bf8218fea
fix(auth): harden persistent sessions
2026-08-16 21:03:07 +02:00
marcopan
ab61c1ad6d
feat(auth): persist opaque remembered sessions
2026-08-16 20:28:32 +02:00
marcopan
b80a2cc1e9
fix(auth): protect local registry directory
2026-08-16 20:11:30 +02:00
marcopan
de8844a4ac
fix(auth): bound local password encoding
2026-08-16 20:03:40 +02:00
marcopan
1ed1a34ae2
fix(auth): reject ill-formed local passwords
2026-08-16 19:56:43 +02:00
marcopan
5eed4f9449
feat(auth): verify local ThothII users in the backend
2026-08-16 19:49:02 +02:00
marcopan
f99bddcdf0
fix(auth): restore permission boundary safeguards
2026-08-16 18:03:36 +02:00
marcopan
2e0489ce22
feat(auth): centralize ThothII permission enforcement
2026-08-16 17:52:03 +02:00
marcopan
e54ce15426
fix(auth): fail closed configuration compatibility
2026-08-16 17:35:40 +02:00
marcopan
a66ef58766
feat(auth): define strict installation authentication config
2026-08-16 17:26:31 +02:00
User
b454fb478b
fix(backend): harden principal child isolation
2026-07-16 18:38:40 +02:00
User
458eb13c89
feat(backend): enforce user-owned sessions
2026-07-16 18:32:52 +02:00
marcopan
a3a266fd81
fix(deploy): close container final review
2026-07-12 00:44:39 +02:00
marcopan and Claude Opus 4.8
a58fb19340
feat(backend): pluggable auth (none/mock/oidc seam)
...
- authPreHandler(mode) returns Fastify preHandler that sets req.user={id}
- none: uses dev@local
- mock: reads x-mock-user header
- oidc: MVP stub returns 501 + throws
- getUser(req) returns user object
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-06-27 21:13:26 +02:00