# Authentication manual acceptance This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin PSD test identity supplied through the approved test-identity process. Record only sanitized pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples. Keep the retained result under `.artifacts/manual-acceptance/authentication//` with a sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or unbounded logs. If the approved identities or access are unavailable, record **PENDING** rather than inferring a PASS. ## Preconditions and ordering 1. Confirm retained Task 13 evidence for the restore prerequisites before certification: the lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are staged/revalidated inside that lock immediately before extraction, and checkpointing requires an opaque installation-bound transaction capability. Manual acceptance never substitutes for those automated concurrency and mutation tests. 2. Run Workspace Validate first; it is the static authentication gate. Run `tht auth check` for live non-interactive diagnosis, then `tht auth check --interactive` where Device Authorization is available, then Workspace Test for aggregate live validation. 3. Run `tht doctor --json` and confirm this exact report order: `descriptor`, `files`, `docker`, `compose`, `configuration`, `authentication`, `services`, `core-http`, `frontend-http`, `workspace-registry`, `workflow`, `pi`. 4. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user` and `TOT Admin → admin`. Confirm extra upstream groups are ignored without warning. ## Matrix | Scenario | Expected result | |---|---| | Ordinary identity opens its own application/session routes | Allowed; admin-only routes return `403`. | | Admin identity opens admin routes | Allowed according to the `admin` permission set. | | Browser callback token omits `groups` | Callback returns HTTP 401 `oidc_callback_failed`; the internal reason is not exposed. | | Browser callback token has malformed, indirect, or overage groups | Callback returns HTTP 401 `oidc_callback_failed`; the internal reason is not exposed. | | Interactive diagnostic receives missing or invalid groups | Diagnostic fails with `oidc_groups_claim_invalid`. | | Token has no mapped group | Principal has no role; protected routes return `403`; no warning is emitted. | | A configured group is absent from Authentik | Check fails with `oidc_mapped_group_missing`. | | Catalog token is wrong or lacks group-view-only access | Live check fails redacted with `oidc_group_catalog_unauthorized`. | | Mapped group is renamed | The next check fails closed until configuration and provider agree. | | Token adds an unrelated group | Login and authorization are unchanged; no warning is emitted. | | Backend restarts with Remember me | Remembered local session survives within its TTL. | | Password/role/enable revision changes | Affected local sessions are rejected and reauthentication is required. | | CSRF or cross-origin mutation is attempted | Request is rejected. | | Logout | Cookie expires and the server session is deleted. | | Provider outage | Live check reports `oidc_discovery_unreachable`; browser login fails closed without exposing credentials. | | Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. | ## Status at Task 15 The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list surface and the complete OIDC Authorization Code + PKCE callback, including direct `groups` fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance. Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive device acceptance, and external L2 remain **PENDING** until actual retained evidence exists. Do not mark the feature or this matrix release-complete while any required gate remains pending.