Complete identity smoke path: id_token claims, registration entry, cutover docs
Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL), AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
This commit is contained in:
parent
3bc16b581b
commit
29a9ff735e
14 changed files with 513 additions and 41 deletions
|
|
@ -1,23 +1,101 @@
|
|||
# Identity smoke checklist
|
||||
|
||||
## Offline (dev claims)
|
||||
Evidence updated: **2026-08-09**.
|
||||
|
||||
1. `uv sync && uv run manage.py migrate && uv run manage.py runserver 8008`
|
||||
2. Open `/` → **Sign in**
|
||||
3. Dev form → submit subject `smoke-1`
|
||||
4. Land on `/app/` with display name and subject shown
|
||||
5. **Sign out** → back to landing; `/app/` redirects to login
|
||||
6. Sign in again with same subject → single `Member` row (idempotent)
|
||||
## Offline (dev claims) — **passed**
|
||||
|
||||
## With platform OIDC
|
||||
```bash
|
||||
uv sync && uv run manage.py migrate && make run
|
||||
# OIDC_ENABLED=false (default), DEBUG=true
|
||||
```
|
||||
|
||||
1. Set `OIDC_ENABLED=true` and issuer/client/redirect env vars
|
||||
2. Register redirect URI at the issuer (no wildcards)
|
||||
3. `/auth/login/` redirects to IdP; callback creates/links Member
|
||||
4. Logout clears app session
|
||||
| Step | Result |
|
||||
|------|--------|
|
||||
| Open `/` → **Sign in** | → `/auth/dev-login/` |
|
||||
| Dev form subject `smoke-1` | 302 → `/app/` |
|
||||
| Shell shows display name + subject | OK |
|
||||
| **Sign out** | session cleared |
|
||||
| `/app/` after logout | 302 → login |
|
||||
| Second login same subject | single `Member` row (idempotent) |
|
||||
| `make test` | **15 passed** |
|
||||
|
||||
Automated POST probe (2026-08-09):
|
||||
|
||||
```text
|
||||
dev_login_post → /app/ 200 with subject smoke-1
|
||||
logout → app 302 to /auth/login/?next=/app/
|
||||
```
|
||||
|
||||
## Cluster in-cluster (port-forward) — **passed (start of OIDC)**
|
||||
|
||||
DNS for `coulomb.social` still points at Cloudflare/Bubble; TLS ACME is
|
||||
blocked until cutover. Smoke via:
|
||||
|
||||
```bash
|
||||
kubectl -n coulomb-social port-forward svc/coulomb-social 18088:80
|
||||
curl -H 'Host: coulomb.social' http://127.0.0.1:18088/healthz
|
||||
# {"status": "ok", "service": "coulomb-social"}
|
||||
```
|
||||
|
||||
| Check | Result |
|
||||
|-------|--------|
|
||||
| Image | `forgejo.coulomb.social/coulomb/coulomb-social:7067145` |
|
||||
| `OIDC_ENABLED` | `true` (values) |
|
||||
| `GET /healthz` + Host | 200 JSON ok |
|
||||
| `GET /` + Host | 200 landing shell |
|
||||
| `GET /auth/login/` + Host | **302** → `https://kc.coulomb.social/authorize?...` with `client_id=coulomb-social`, `redirect_uri=https://coulomb.social/auth/callback/`, PKCE S256 |
|
||||
| Session cookie | `HttpOnly; Secure; SameSite=Lax` (prod settings) |
|
||||
|
||||
Full browser login against the **cluster** redirect URI requires public HTTPS
|
||||
on `coulomb.social` (Secure cookie + callback host). Use **local OIDC** below
|
||||
before DNS cutover, or complete browser MFA after cutover.
|
||||
|
||||
## Platform OIDC (local redirect) — **ready for human MFA**
|
||||
|
||||
Client registration and authorize handoff verified; **human Authelia + MFA**
|
||||
is the remaining interactive step.
|
||||
|
||||
```bash
|
||||
export OIDC_ENABLED=true
|
||||
export OIDC_ISSUER=https://kc.coulomb.social
|
||||
export OIDC_CLIENT_ID=coulomb-social
|
||||
export OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
|
||||
export OIDC_SCOPES="openid profile email groups"
|
||||
# optional live user-engine (else stub):
|
||||
# export USER_ENGINE_BASE_URL=https://users.92-205-62-239.nip.io
|
||||
# export USER_ENGINE_PROXY_SECRET="$(kubectl -n user-engine get secret user-engine-runtime \
|
||||
# -o jsonpath='{.data.proxy-secret}' | base64 -d)"
|
||||
make run
|
||||
```
|
||||
|
||||
| Step | Expected |
|
||||
|------|----------|
|
||||
| Open http://127.0.0.1:8008/ → Sign in | redirect KeyCape → Authelia |
|
||||
| Complete MFA | callback → `/app/` with subject / display name |
|
||||
| Sign out | landing; `/app/` requires login |
|
||||
| Second login | same Member / user_engine user_id |
|
||||
|
||||
Authorize probe (no browser) 2026-08-09:
|
||||
|
||||
| redirect_uri | KeyCape |
|
||||
|--------------|---------|
|
||||
| `http://127.0.0.1:8008/auth/callback/` | **302** → Authelia OIDC |
|
||||
| `https://coulomb.social/auth/callback/` | **302** → Authelia OIDC |
|
||||
|
||||
Unregistered redirects still fail with `invalid_profile_usage` (T03).
|
||||
|
||||
## Automated
|
||||
|
||||
```bash
|
||||
make test
|
||||
```
|
||||
|
||||
## Blockers for production hostname smoke
|
||||
|
||||
| Blocker | Detail |
|
||||
|---------|--------|
|
||||
| Public DNS | `coulomb.social` → Cloudflare `104.*` (Bubble), not `92.205.62.239` |
|
||||
| TLS cert | `certificate/coulomb-social-tls` **not Ready**; HTTP-01 challenge gets **404** from public edge (LE never reaches cluster solver) |
|
||||
| Secure cookies | prod `SESSION_COOKIE_SECURE=True` — need HTTPS after cutover |
|
||||
|
||||
See cutover steps in `docs/deploy.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue