109 lines
3.1 KiB
Markdown
109 lines
3.1 KiB
Markdown
# PSD Server Project B — Acceptance Report
|
|
|
|
> Template only. Store raw Authentik exports, database backups, browser traces, and server topology
|
|
> only in protected server storage. Never retain passwords, provider/client secrets, API tokens,
|
|
> cookies, raw claims, callback query strings, private keys, patient-identifying data, or unbounded
|
|
> logs in this report.
|
|
|
|
## Decision
|
|
|
|
- Result: `PROJECT_B_PASS` / `PROJECT_B_FAIL` / `PROJECT_B_PENDING`
|
|
- Decision timestamp UTC:
|
|
- Owner/reviewer:
|
|
- Protected evidence path:
|
|
- Evidence manifest SHA-256:
|
|
- Accepted Project A report digest:
|
|
|
|
## Frozen candidate
|
|
|
|
- ThothII source SHA:
|
|
- Workspace SHA:
|
|
- Core/frontend image identities:
|
|
- Qdrant/Ollama image identities:
|
|
- Pi provider/model:
|
|
- Public origin:
|
|
- Aritmolab source/deployment revision:
|
|
|
|
## Authentik
|
|
|
|
- Installed version:
|
|
- Pre-change export reference/checksum:
|
|
- Application name/ID:
|
|
- Provider name/ID:
|
|
- Issuer:
|
|
- Callback path verified:
|
|
- Grant types/scopes verified:
|
|
- Direct groups claim shape verified:
|
|
- User group name/ID:
|
|
- Admin group name/ID:
|
|
- Group-catalog service account name/ID:
|
|
- Least-privilege result:
|
|
- `auth check --json` result:
|
|
- Interactive device check: PASS/FAIL/PENDING
|
|
- No secret/raw claim in evidence: PASS/FAIL
|
|
|
|
## Supabase session storage
|
|
|
|
- Existing database name:
|
|
- Session schema: thoth_sessions
|
|
- Backup reference/checksum:
|
|
- Migration result (`pending=[]`, `drifted=[]`):
|
|
- Migration idempotency:
|
|
- Runtime role security/RLS result:
|
|
- Migrator absent from core:
|
|
- PostgREST exposed schemas proof:
|
|
- `thoth_sessions` not REST-exposed: PASS/FAIL
|
|
- DWH `datawarehouse` privileges unchanged: PASS/FAIL
|
|
|
|
## Nginx, TLS, load balancer, and Aritmolab
|
|
|
|
- Nginx configuration file/revision:
|
|
- `nginx -t` result:
|
|
- Certificate subject/SAN/expiry metadata:
|
|
- Certificate trust result:
|
|
- Load-balancer route/health result:
|
|
- Same-origin API/callback result:
|
|
- SSE unbuffered result:
|
|
- No double `auth_request`: PASS/FAIL
|
|
- Sidebar source/link result:
|
|
- Other virtual hosts unchanged: PASS/FAIL
|
|
|
|
## Human SSO and authorization
|
|
|
|
- Aritmolab login → sidebar → ThothII without second credential prompt:
|
|
- Ordinary user permissions:
|
|
- Administrator permissions:
|
|
- No-role user result:
|
|
- Extra unrelated group result:
|
|
- Missing/malformed group negative result:
|
|
- Forged-header result:
|
|
- ThothII logout result:
|
|
- Authentik SSO session behavior documented:
|
|
- Provider/catalog controlled failure and recovery:
|
|
- Manual guide result and reviewer:
|
|
|
|
## OIDC F1-F8 session and ownership
|
|
|
|
- Approved sanitized question reference:
|
|
- Session ID:
|
|
- OIDC principal reference (non-identifying):
|
|
- F1-F8/final SQL result:
|
|
- PostgreSQL manifest/artifact/decision persistence:
|
|
- Resume/restart result:
|
|
- Cross-user isolation result:
|
|
- Admin cross-user result:
|
|
- Chat/SSE ephemeral boundary:
|
|
|
|
## Rollback, cleanup, and hygiene
|
|
|
|
- Ingress-first rollback rehearsal:
|
|
- Project A protected configuration available:
|
|
- Authentik disable plan verified:
|
|
- Additive schema rollback boundary verified:
|
|
- Project A temporary endpoint removed:
|
|
- Legacy stack stopped/unexposed:
|
|
- Core/Qdrant/Ollama private:
|
|
- Secret scan result:
|
|
- Unrelated failures or pending items:
|
|
- Reason for final decision:
|