Files
ThothII/docs/testing/authentication-manual-acceptance.md
T

4.7 KiB

Authentication manual acceptance

This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin PSD test identity supplied through the approved test-identity process. Record only sanitized pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples. Keep the retained result under .artifacts/manual-acceptance/authentication/<run-id>/ with a sanitized digest. Do not retain raw browser traces, Compose environments, provider exports, or unbounded logs. If the approved identities or access are unavailable, record PENDING rather than inferring a PASS.

Preconditions and ordering

  1. Confirm retained Task 13 evidence for the restore prerequisites before certification: the lifecycle lock is acquired before target-dependent preflight, archive bytes and hashes are staged/revalidated inside that lock immediately before extraction, and checkpointing requires an opaque installation-bound transaction capability. Manual acceptance never substitutes for those automated concurrency and mutation tests.

  2. Set the installation and workspace identifiers, then inspect the active workspace with the native host CLI. This replaces the former Workspace Validate/Test wording:

    export THT_BIN=tht
    export INSTALLATION=/absolute/path/to/thothii-installation.yaml
    export WORKSPACE_ID=psd-clinical
    "$THT_BIN" --installation "$INSTALLATION" \
      workspace inspect --workspace "$WORKSPACE_ID" --json
    
  3. Run "$THT_BIN" --installation "$INSTALLATION" auth check --json for live non-interactive diagnosis, then auth check --interactive where Device Authorization is available.

  4. Run "$THT_BIN" --installation "$INSTALLATION" doctor --json and confirm this exact report order: descriptor, files, docker, compose, configuration, authentication, services, core-http, frontend-http, workspace-registry, workflow, pi.

  5. Confirm the exact direct groups claim for both identities and the mappings TOT Users → user and TOT Admin → admin. Confirm extra upstream groups are ignored without warning.

Matrix

Scenario Expected result
Ordinary identity opens its own application/session routes Allowed; admin-only routes return 403.
Admin identity opens admin routes Allowed according to the admin permission set.
Browser callback token omits groups Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed.
Browser callback token has malformed, indirect, or overage groups Callback returns HTTP 401 oidc_callback_failed; the internal reason is not exposed.
Interactive diagnostic receives missing or invalid groups Diagnostic fails with oidc_groups_claim_invalid.
Token has no mapped group Principal has no role; protected routes return 403; no warning is emitted.
A configured group is absent from Authentik Check fails with oidc_mapped_group_missing.
Catalog token is wrong or lacks group-view-only access Live check fails redacted with oidc_group_catalog_unauthorized.
Mapped group is renamed The next check fails closed until configuration and provider agree.
Token adds an unrelated group Login and authorization are unchanged; no warning is emitted.
Authenticated PSD identity creates a known-good session SSE connects, the session is created, and the first reviewer gate appears without unexpected 401/403 responses.
Backend restarts with Remember me Remembered local session survives within its TTL.
Password/role/enable revision changes Affected local sessions are rejected and reauthentication is required.
CSRF or cross-origin mutation is attempted Request is rejected.
Logout Cookie expires and the server session is deleted.
Provider outage Live check reports oidc_discovery_unreachable; browser login fails closed without exposing credentials.
Restore is completed Sessions and OIDC state are absent; all users must reauthenticate.

Status at Task 15

The hermetic browser suite now covers the loopback provider discovery/JWKS/device/group-list surface and the complete OIDC Authorization Code + PKCE callback, including direct groups fail-closed cases. It also covers local ordinary, remembered/restart, logout, and administrator flows. This deterministic evidence does not replace the manual PSD/AuthentiK acceptance.

Native Windows behavioral execution, approved PSD/AuthentiK identities and access, interactive device acceptance, and external L2 remain PENDING until actual retained evidence exists. Do not mark the feature or this matrix release-complete while any required gate remains pending.