4.7 KiB
Authentication manual acceptance
This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin
PSD test identity supplied through the approved test-identity process. Record only sanitized
pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal
URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples.
Keep the retained result under .artifacts/manual-acceptance/authentication/<run-id>/ with a
sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or
unbounded logs. If the approved identities or access are unavailable, record PENDING rather
than inferring a PASS.
Preconditions and ordering
-
Confirm retained Task 13 evidence for the restore prerequisites before certification: the lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are staged/revalidated inside that lock immediately before extraction, and checkpointing requires an opaque installation-bound transaction capability. Manual acceptance never substitutes for those automated concurrency and mutation tests.
-
Set the installation and workspace identifiers, then inspect the active workspace with the native host CLI. This replaces the former Workspace Validate/Test wording:
export THT_BIN=tht export INSTALLATION=/absolute/path/to/thothii-installation.yaml export WORKSPACE_ID=psd-clinical "$THT_BIN" --installation "$INSTALLATION" \ workspace inspect --workspace "$WORKSPACE_ID" --json -
Run
"$THT_BIN" --installation "$INSTALLATION" auth check --jsonfor live non-interactive diagnosis, thenauth check --interactivewhere Device Authorization is available. -
Run
"$THT_BIN" --installation "$INSTALLATION" doctor --jsonand confirm this exact report order:descriptor,files,docker,compose,configuration,authentication,services,core-http,frontend-http,workspace-registry,workflow,pi. -
Confirm the exact direct
groupsclaim for both identities and the mappingsTOT Users → userandTOT Admin → admin. Confirm extra upstream groups are ignored without warning.
Matrix
| Scenario | Expected result |
|---|---|
| Ordinary identity opens its own application/session routes | Allowed; admin-only routes return 403. |
| Admin identity opens admin routes | Allowed according to the admin permission set. |
Browser callback token omits groups |
Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed. |
| Browser callback token has malformed, indirect, or overage groups | Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed. |
| Interactive diagnostic receives missing or invalid groups | Diagnostic fails with oidc_groups_claim_invalid. |
| Token has no mapped group | Principal has no role; protected routes return 403; no warning is emitted. |
| A configured group is absent from Authentik | Check fails with oidc_mapped_group_missing. |
| Catalog token is wrong or lacks group-view-only access | Live check fails redacted with oidc_group_catalog_unauthorized. |
| Mapped group is renamed | The next check fails closed until configuration and provider agree. |
| Token adds an unrelated group | Login and authorization are unchanged; no warning is emitted. |
| Authenticated PSD identity creates a known-good session | SSE connects, the session is created, and the first reviewer gate appears without unexpected 401/403 responses. |
| Backend restarts with Remember me | Remembered local session survives within its TTL. |
| Password/role/enable revision changes | Affected local sessions are rejected and reauthentication is required. |
| CSRF or cross-origin mutation is attempted | Request is rejected. |
| Logout | Cookie expires and the server session is deleted. |
| Provider outage | Live check reports oidc_discovery_unreachable; browser login fails closed without exposing credentials. |
| Restore is completed | Sessions and OIDC state are absent; all users must reauthenticate. |
Status at Task 15
The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list
surface and the complete OIDC Authorization Code + PKCE callback, including direct groups
fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator
flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance.
Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive device acceptance, and external L2 remain PENDING until actual retained evidence exists. Do not mark the feature or this matrix release-complete while any required gate remains pending.