70 lines
4.7 KiB
Markdown
70 lines
4.7 KiB
Markdown
# Authentication manual acceptance
|
|
|
|
This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin
|
|
PSD test identity supplied through the approved test-identity process. Record only sanitized
|
|
pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal
|
|
URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples.
|
|
Keep the retained result under `.artifacts/manual-acceptance/authentication/<run-id>/` with a
|
|
sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or
|
|
unbounded logs. If the approved identities or access are unavailable, record **PENDING** rather
|
|
than inferring a PASS.
|
|
|
|
## Preconditions and ordering
|
|
|
|
1. Confirm retained Task 13 evidence for the restore prerequisites before certification: the
|
|
lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are
|
|
staged/revalidated inside that lock immediately before extraction, and checkpointing requires
|
|
an opaque installation-bound transaction capability. Manual acceptance never substitutes for
|
|
those automated concurrency and mutation tests.
|
|
2. Set the installation and workspace identifiers, then inspect the active workspace with the
|
|
native host CLI. This replaces the former Workspace Validate/Test wording:
|
|
|
|
```bash
|
|
export THT_BIN=tht
|
|
export INSTALLATION=/absolute/path/to/thothii-installation.yaml
|
|
export WORKSPACE_ID=psd-clinical
|
|
"$THT_BIN" --installation "$INSTALLATION" \
|
|
workspace inspect --workspace "$WORKSPACE_ID" --json
|
|
```
|
|
|
|
3. Run `"$THT_BIN" --installation "$INSTALLATION" auth check --json` for live non-interactive
|
|
diagnosis, then `auth check --interactive` where Device Authorization is available.
|
|
4. Run `"$THT_BIN" --installation "$INSTALLATION" doctor --json` and confirm this exact report order: `descriptor`, `files`, `docker`,
|
|
`compose`, `configuration`, `authentication`, `services`, `core-http`, `frontend-http`,
|
|
`workspace-registry`, `workflow`, `pi`.
|
|
4. Confirm the exact direct `groups` claim for both identities and the mappings `TOT Users → user`
|
|
and `TOT Admin → admin`. Confirm extra upstream groups are ignored without warning.
|
|
|
|
## Matrix
|
|
|
|
| Scenario | Expected result |
|
|
|---|---|
|
|
| Ordinary identity opens its own application/session routes | Allowed; admin-only routes return `403`. |
|
|
| Admin identity opens admin routes | Allowed according to the `admin` permission set. |
|
|
| Browser callback token omits `groups` | Callback returns HTTP 401 `oidc_callback_failed`; the internal reason is not exposed. |
|
|
| Browser callback token has malformed, indirect, or overage groups | Callback returns HTTP 401 `oidc_callback_failed`; the internal reason is not exposed. |
|
|
| Interactive diagnostic receives missing or invalid groups | Diagnostic fails with `oidc_groups_claim_invalid`. |
|
|
| Token has no mapped group | Principal has no role; protected routes return `403`; no warning is emitted. |
|
|
| A configured group is absent from Authentik | Check fails with `oidc_mapped_group_missing`. |
|
|
| Catalog token is wrong or lacks group-view-only access | Live check fails redacted with `oidc_group_catalog_unauthorized`. |
|
|
| Mapped group is renamed | The next check fails closed until configuration and provider agree. |
|
|
| Token adds an unrelated group | Login and authorization are unchanged; no warning is emitted. |
|
|
| Authenticated PSD identity creates a known-good session | SSE connects, the session is created, and the first reviewer gate appears without unexpected `401`/`403` responses. |
|
|
| Backend restarts with Remember me | Remembered local session survives within its TTL. |
|
|
| Password/role/enable revision changes | Affected local sessions are rejected and reauthentication is required. |
|
|
| CSRF or cross-origin mutation is attempted | Request is rejected. |
|
|
| Logout | Cookie expires and the server session is deleted. |
|
|
| Provider outage | Live check reports `oidc_discovery_unreachable`; browser login fails closed without exposing credentials. |
|
|
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
|
|
|
|
## Status at Task 15
|
|
|
|
The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list
|
|
surface and the complete OIDC Authorization Code + PKCE callback, including direct `groups`
|
|
fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator
|
|
flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance.
|
|
|
|
Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive
|
|
device acceptance, and external L2 remain **PENDING** until actual retained evidence exists. Do
|
|
not mark the feature or this matrix release-complete while any required gate remains pending.
|