Plan product path: app shell and Forgejo markdown spaces
Mark CSOC-WP-0002 identity done on app.coulomb.social. Defer bulk Bubble migration until product foundation exists. Open CSOC-WP-0004 for post-login entry and space content as markdown bound to Forgejo.
This commit is contained in:
parent
f5537d8365
commit
d36795faa6
7 changed files with 288 additions and 84 deletions
|
|
@ -5,10 +5,10 @@ title: "Add NetKingdom self-registration and profile-aware assurance"
|
|||
domain: communication
|
||||
repo: coulomb-social
|
||||
status: active
|
||||
owner: codex
|
||||
owner: bernd
|
||||
topic_slug: coulomb-social
|
||||
created: "2026-08-09"
|
||||
updated: "2026-08-09"
|
||||
updated: "2026-08-10"
|
||||
depends_on:
|
||||
- CSOC-WP-0002
|
||||
- NK-WP-0025
|
||||
|
|
@ -22,6 +22,11 @@ state_hub_workstream_id: "7cd7d6b8-e01d-4b34-8680-3c0cac68d80e"
|
|||
Extend the working CSOC-WP-0002 OIDC/JIT shell with a NetKingdom account
|
||||
creation entry point and optional profile/action step-up.
|
||||
|
||||
**2026-08-10 posture:** existing-user login on **`app.coulomb.social`** is proven
|
||||
(tegwick, AAL1, no MFA). Public **Create account** remains blocked on NetKingdom
|
||||
mailbox verification (NK-WP-0025 / USER-WP-0022). Product work proceeds via
|
||||
`CSOC-WP-0004` without waiting on public registration.
|
||||
|
||||
## T01 - Preserve and prove first-login JIT profile creation
|
||||
|
||||
```task
|
||||
|
|
@ -31,35 +36,24 @@ priority: high
|
|||
state_hub_task_id: "dde13170-7203-4fcd-b0ce-5874fccc4632"
|
||||
```
|
||||
|
||||
Harden the existing issuer/subject keyed Member creation, concurrent callback
|
||||
behavior, verified ID-token processing, and user-engine link. Preserve the
|
||||
current uncommitted CSOC-WP-0002 claim-verification work.
|
||||
Harden issuer/subject keyed Member creation, concurrent callback behavior,
|
||||
verified ID-token processing, and user-engine link.
|
||||
|
||||
Done when an existing LLDAP identity gets exactly one ordinary Member and
|
||||
repeat login updates safe display fields without changing identity ownership.
|
||||
|
||||
Covered by the issuer/subject uniqueness constraint, unusable local passwords,
|
||||
idempotent session establishment tests, and verified ID-token claim handling.
|
||||
**2026-08-10 evidence:** live login on app.coulomb.social shows principal +
|
||||
user-engine id; image `:f5537d8` uses id_token when `/userinfo` 401s.
|
||||
|
||||
## T02 - Add Create NetKingdom account
|
||||
|
||||
```task
|
||||
id: CSOC-WP-0003-T02
|
||||
status: progress
|
||||
priority: high
|
||||
priority: medium
|
||||
state_hub_task_id: "aaf2d2cb-6ba9-42cb-9271-aacc414e947a"
|
||||
```
|
||||
|
||||
Add a landing-page registration choice using the configured NetKingdom public
|
||||
registration URL. The configured URL owns any signed return context. Completion must
|
||||
start a fresh OIDC flow before creating an application session.
|
||||
|
||||
Done when a new user can leave coulomb.social, register, and return through
|
||||
the same callback/JIT path without open redirects.
|
||||
|
||||
The application entry point is implemented and ignores browser-supplied
|
||||
redirect parameters. It remains disabled until the NetKingdom public
|
||||
registration URL and verified-mail flow are deployed.
|
||||
Landing-page **Create account** using configured `NETKINGDOM_REGISTRATION_URL`.
|
||||
App entry is implemented; remains disabled until NetKingdom public registration
|
||||
URL + verified-mail flow ship.
|
||||
|
||||
## T03 - Support profile/action step-up
|
||||
|
||||
|
|
@ -70,27 +64,22 @@ priority: high
|
|||
state_hub_task_id: "6636a746-02ca-4a70-ac3c-0219c89cd6a7"
|
||||
```
|
||||
|
||||
Use AAL1 for ordinary member sessions. When profile policy or a protected
|
||||
action requires MFA, restart authorization with AAL2 acr_values and verify the
|
||||
returned assurance claim before completing the action.
|
||||
|
||||
Done when tegwick can use ordinary login without MFA and opt into or encounter
|
||||
MFA step-up without affecting another member.
|
||||
|
||||
Implemented explicit `?assurance=aal2`, OIDC `acr_values`, and callback-side
|
||||
assurance validation. Ordinary login sends no ACR request.
|
||||
AAL1 ordinary sessions; AAL2 via `acr_values` when required. Live coulomb-social
|
||||
client uses `mfaRequired: false`.
|
||||
|
||||
## T04 - Deploy and run Case A / Case B matrix
|
||||
|
||||
```task
|
||||
id: CSOC-WP-0003-T04
|
||||
status: todo
|
||||
priority: high
|
||||
status: progress
|
||||
priority: medium
|
||||
state_hub_task_id: "57bac5f4-fd5d-46ba-92a3-a7bbeb15aa08"
|
||||
```
|
||||
|
||||
Test known LLDAP user, new registration, repeated/concurrent callback,
|
||||
email collision, state replay, disabled identity, local-account coexistence,
|
||||
password-only login, AAL2 step-up, logout, and rollback on railiance01.
|
||||
| Case | Status |
|
||||
|------|--------|
|
||||
| A — known LLDAP user, first/repeat login on app.* | **done** (tegwick) |
|
||||
| B — brand-new public registration → OIDC → Member | **blocked** on NK mailbox verification |
|
||||
|
||||
Done when both requested cases pass with non-secret evidence.
|
||||
Record remaining negatives (state replay, collision, step-up) when Case B unblocks
|
||||
or in a short follow-up smoke note under `docs/identity/smoke.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue