Files
ThothII/docs/testing/authentication-manual-acceptance.md
T

3.1 KiB

Authentication manual acceptance

This is a release-gate checklist, not evidence. Use one ordinary PSD test identity and one admin PSD test identity supplied through the approved test-identity process. Record only sanitized pass/fail results, timestamps, build identity, and diagnostic codes. Do not record names, internal URLs, directory/LDAP details, tokens, passwords, hashes, cookies, or realistic secret examples.

Preconditions and ordering

  1. Resolve the two parked Task 13 restore preconditions before certification: acquire the lifecycle lock before any target-dependent preflight and stage/revalidate archive bytes and hashes inside that lock immediately before extraction; replace convention-only createWithDependenciesLockHeld with an opaque installation-bound transaction capability or closure so lock-held primitives cannot be called without the capability.
  2. Run tht auth check, then tht auth check --interactive where Device Authorization is available, then workspace Validate and workspace Test. Run tht doctor --json and confirm its authentication check precedes service and workspace checks.
  3. Confirm the exact direct groups claim for both identities and the mappings TOT Users → user and TOT Admin → admin. Confirm extra upstream groups are ignored without warning.

Matrix

Scenario Expected result
Ordinary identity opens its own application/session routes Allowed; admin-only routes return 403.
Admin identity opens admin routes Allowed according to the admin permission set.
Token omits groups Authentication fails closed with oidc_groups_claim_invalid.
Token has malformed, indirect, or overage groups Authentication fails closed with oidc_groups_claim_invalid.
Token has no mapped group Principal has no role; protected routes return 403; no warning is emitted.
A configured group is absent from Authentik Check fails with oidc_mapped_group_missing.
Catalog token is wrong or lacks group-view-only access Check fails redacted as catalog unavailable/unauthorized.
Mapped group is renamed The next check fails closed until configuration and provider agree.
Token adds an unrelated group Login and authorization are unchanged; no warning is emitted.
Backend restarts with Remember me Remembered local session survives within its TTL.
Password/role/enable revision changes Affected local sessions are rejected and reauthentication is required.
CSRF or cross-origin mutation is attempted Request is rejected.
Logout Cookie expires and the server session is deleted.
Provider outage Live check and OIDC login fail closed; no credential is exposed.
Restore is completed Sessions and OIDC state are absent; all users must reauthenticate.

Status at Task 14

Documentation and deterministic contract checks are the Task 14 scope. Browser OIDC callback E2E, native Windows behavioral execution, the two parked restore-lock preconditions above, PSD/manual identities, and any external L2 execution remain pending Task 15/release gates. Do not mark this matrix PASS until those gates have actual retained evidence.