Files
ThothII/docs/testing/authentication-manual-acceptance.md
T

4.2 KiB

Authentication manual acceptance

This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin PSD test identity supplied through the approved test-identity process. Record only sanitized pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples. Keep the retained result under .artifacts/manual-acceptance/authentication/<run-id>/ with a sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or unbounded logs. If the approved identities or access are unavailable, record PENDING rather than inferring a PASS.

Preconditions and ordering

  1. Confirm retained Task 13 evidence for the restore prerequisites before certification: the lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are staged/revalidated inside that lock immediately before extraction, and checkpointing requires an opaque installation-bound transaction capability. Manual acceptance never substitutes for those automated concurrency and mutation tests.
  2. Run Workspace Validate first; it is the static authentication gate. Run tht auth check for live non-interactive diagnosis, then tht auth check --interactive where Device Authorization is available, then Workspace Test for aggregate live validation.
  3. Run tht doctor --json and confirm this exact report order: descriptor, files, docker, compose, configuration, authentication, services, core-http, frontend-http, workspace-registry, workflow, pi.
  4. Confirm the exact direct groups claim for both identities and the mappings TOT Users → user and TOT Admin → admin. Confirm extra upstream groups are ignored without warning.

Matrix

Scenario Expected result
Ordinary identity opens its own application/session routes Allowed; admin-only routes return 403.
Admin identity opens admin routes Allowed according to the admin permission set.
Browser callback token omits groups Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed.
Browser callback token has malformed, indirect, or overage groups Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed.
Interactive diagnostic receives missing or invalid groups Diagnostic fails with oidc_groups_claim_invalid.
Token has no mapped group Principal has no role; protected routes return 403; no warning is emitted.
A configured group is absent from Authentik Check fails with oidc_mapped_group_missing.
Catalog token is wrong or lacks group-view-only access Live check fails redacted with oidc_group_catalog_unauthorized.
Mapped group is renamed The next check fails closed until configuration and provider agree.
Token adds an unrelated group Login and authorization are unchanged; no warning is emitted.
Backend restarts with Remember me Remembered local session survives within its TTL.
Password/role/enable revision changes Affected local sessions are rejected and reauthentication is required.
CSRF or cross-origin mutation is attempted Request is rejected.
Logout Cookie expires and the server session is deleted.
Provider outage Live check reports oidc_discovery_unreachable; browser login fails closed without exposing credentials.
Restore is completed Sessions and OIDC state are absent; all users must reauthenticate.

Status at Task 15

The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list surface and the complete OIDC Authorization Code + PKCE callback, including direct groups fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance.

Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive device acceptance, and external L2 remain PENDING until actual retained evidence exists. Do not mark the feature or this matrix release-complete while any required gate remains pending.