# PSD Server Project B — Acceptance Report > Template only. Store raw Authentik exports, database backups, browser traces, and server topology > only in protected server storage. Never retain passwords, provider/client secrets, API tokens, > cookies, raw claims, callback query strings, private keys, patient-identifying data, or unbounded > logs in this report. ## Decision - Result: `PROJECT_B_PASS` / `PROJECT_B_FAIL` / `PROJECT_B_PENDING` - Decision timestamp UTC: - Owner/reviewer: - Protected evidence path: - Evidence manifest SHA-256: - Accepted Project A report digest: ## Frozen candidate - ThothII source SHA: - Workspace SHA: - Core/frontend image identities: - Qdrant/Ollama image identities: - Pi provider/model: - Public origin: - Aritmolab source/deployment revision: ## Authentik - Installed version: - Pre-change export reference/checksum: - Application name/ID: - Provider name/ID: - Issuer: - Callback path verified: - Grant types/scopes verified: - Direct groups claim shape verified: - User group name/ID: - Admin group name/ID: - Group-catalog service account name/ID: - Least-privilege result: - `auth check --json` result: - Interactive device check: PASS/FAIL/PENDING - No secret/raw claim in evidence: PASS/FAIL ## Supabase session storage - Existing database name: - Session schema: thoth_sessions - Backup reference/checksum: - Migration result (`pending=[]`, `drifted=[]`): - Migration idempotency: - Runtime role security/RLS result: - Migrator absent from core: - PostgREST exposed schemas proof: - `thoth_sessions` not REST-exposed: PASS/FAIL - DWH `datawarehouse` privileges unchanged: PASS/FAIL ## Nginx, TLS, load balancer, and Aritmolab - Nginx configuration file/revision: - `nginx -t` result: - Certificate subject/SAN/expiry metadata: - Certificate trust result: - Load-balancer route/health result: - Same-origin API/callback result: - SSE unbuffered result: - No double `auth_request`: PASS/FAIL - Sidebar source/link result: - Other virtual hosts unchanged: PASS/FAIL ## Human SSO and authorization - Aritmolab login → sidebar → ThothII without second credential prompt: - Ordinary user permissions: - Administrator permissions: - No-role user result: - Extra unrelated group result: - Missing/malformed group negative result: - Forged-header result: - ThothII logout result: - Authentik SSO session behavior documented: - Provider/catalog controlled failure and recovery: - Manual guide result and reviewer: ## OIDC F1-F8 session and ownership - Approved sanitized question reference: - Session ID: - OIDC principal reference (non-identifying): - F1-F8/final SQL result: - PostgreSQL manifest/artifact/decision persistence: - Resume/restart result: - Cross-user isolation result: - Admin cross-user result: - Chat/SSE ephemeral boundary: ## Rollback, cleanup, and hygiene - Ingress-first rollback rehearsal: - Project A protected configuration available: - Authentik disable plan verified: - Additive schema rollback boundary verified: - Project A temporary endpoint removed: - Legacy stack stopped/unexposed: - Core/Qdrant/Ollama private: - Secret scan result: - Unrelated failures or pending items: - Reason for final decision: