Added workplan and work records
This commit is contained in:
parent
83538084b0
commit
18ec776fba
2 changed files with 154 additions and 0 deletions
41
WORK-RECORDS.md
Normal file
41
WORK-RECORDS.md
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
# Work Records — helix-forge
|
||||
|
||||
> Generated by `statehub fix-consistency` (CUST-WP-0061-T04, work-record
|
||||
> stage 3). Do not edit by hand — edit the source file/block listed for
|
||||
> each record and re-run fix-consistency to refresh this index. Archived
|
||||
> workplans are omitted; closed decisions/intakes/engagements stay listed
|
||||
> so recently-resolved work is still visible. [auto]
|
||||
|
||||
| Kind | ID | Status | Lane | Source |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| workplan | HF-WP-0001 | finished | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| workplan | HF-WP-0002 | finished | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| workplan | HF-WP-0003 | finished | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| workplan | HF-WP-0004 | archived | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
| task | HF-WP-0001-T01 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T02 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T03 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T04 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T05 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T06 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T07 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T08 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T09 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0001-T10 | done | — | workplans/HF-WP-0001-establish-ops-hub-first-extension.md |
|
||||
| task | HF-WP-0002-T01 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0002-T02 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0002-T03 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0002-T04 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0002-T05 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0002-T06 | done | — | workplans/HF-WP-0002-openbao-browser-ui-at-bao-coulomb-social.md |
|
||||
| task | HF-WP-0003-T01 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0003-T02 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0003-T03 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0003-T04 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0003-T05 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0003-T06 | done | — | workplans/HF-WP-0003-openbao-keycape-login-overlay.md |
|
||||
| task | HF-WP-0004-T01 | cancel | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
| task | HF-WP-0004-T02 | cancel | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
| task | HF-WP-0004-T03 | cancel | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
| task | HF-WP-0004-T04 | cancel | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
| task | HF-WP-0004-T05 | cancel | — | workplans/HF-WP-0004-coulomb-social-netkingdom-login-and-jit-profile.md |
|
||||
|
|
@ -0,0 +1,113 @@
|
|||
---
|
||||
id: HF-WP-0004
|
||||
type: workplan
|
||||
title: "Integrate coulomb.social with NetKingdom login and JIT profiles"
|
||||
domain: infotech
|
||||
repo: helix-forge
|
||||
status: archived
|
||||
owner: codex
|
||||
topic_slug: netkingdom
|
||||
created: "2026-08-09"
|
||||
updated: "2026-08-09"
|
||||
depends_on:
|
||||
- NK-WP-0025
|
||||
- USER-WP-0022
|
||||
- KEY-WP-0008
|
||||
state_hub_workstream_id: "ba123393-fccc-48a0-a228-b7d0aa2fd663"
|
||||
---
|
||||
|
||||
# HF-WP-0004 - coulomb.social login and first-login profile
|
||||
|
||||
Add NetKingdom OIDC as an alternative to coulomb.social local registration.
|
||||
The application keeps ownership of its local profile and authorization while
|
||||
using KeyCape for authentication.
|
||||
|
||||
## T01 - Pin the OIDC consumer and account-link contract
|
||||
|
||||
```task
|
||||
id: HF-WP-0004-T01
|
||||
status: cancel
|
||||
priority: high
|
||||
state_hub_task_id: "71db76f0-8842-4e00-a314-ee26669e2ce3"
|
||||
```
|
||||
|
||||
Implement authorization-code plus PKCE against the existing coulomb-social
|
||||
KeyCape client and exact production callback. Store the stable issuer/subject
|
||||
link separately from username and email. Define explicit handling for an
|
||||
existing local account whose verified email matches the OIDC identity.
|
||||
|
||||
Done when email matching cannot silently attach or replace an existing local
|
||||
account.
|
||||
|
||||
## T02 - Create the profile idempotently on first login
|
||||
|
||||
```task
|
||||
id: HF-WP-0004-T02
|
||||
status: cancel
|
||||
priority: high
|
||||
state_hub_task_id: "34d0c78a-08db-49a8-8f5c-71f9a5c15dce"
|
||||
```
|
||||
|
||||
On a valid callback, atomically find-or-create the coulomb.social application
|
||||
profile keyed by issuer/subject, seed ordinary-user defaults, establish the
|
||||
application session, and redirect to the intended page. Repeated callbacks,
|
||||
concurrent tabs, and retries must return the same profile.
|
||||
|
||||
Done when an existing LLDAP user with no application profile can sign in and
|
||||
receive exactly one regular coulomb.social profile.
|
||||
|
||||
## T03 - Add login and registration choices
|
||||
|
||||
```task
|
||||
id: HF-WP-0004-T03
|
||||
status: cancel
|
||||
priority: high
|
||||
state_hub_task_id: "6b33b969-3fad-4579-abc5-0bc3856d12cc"
|
||||
```
|
||||
|
||||
Offer Sign in with NetKingdom, Create NetKingdom account, and the existing
|
||||
local-account path according to product policy. The registration choice uses
|
||||
the signed return flow from NK-WP-0025; completion starts a fresh OIDC login.
|
||||
Avoid user enumeration and open redirects.
|
||||
|
||||
Done when a completely new person can register from the coulomb.social
|
||||
landing page and return as an authenticated regular user.
|
||||
|
||||
## T04 - Enforce profile/action assurance
|
||||
|
||||
```task
|
||||
id: HF-WP-0004-T04
|
||||
status: cancel
|
||||
priority: high
|
||||
state_hub_task_id: "4fc5253a-f485-4259-8cea-ed0968f958e5"
|
||||
```
|
||||
|
||||
Accept password-level assurance for ordinary profiles unless the application
|
||||
profile or requested action requires MFA. For step-up, send a fresh KeyCape
|
||||
authorization request and verify the returned assurance before completing the
|
||||
action. Never infer MFA from email or application session age alone.
|
||||
|
||||
Done when the attended tegwick profile works without MFA by default and can
|
||||
be configured to require MFA without changing another user's profile.
|
||||
|
||||
## T05 - Migrate, deploy, and prove both cases
|
||||
|
||||
```task
|
||||
id: HF-WP-0004-T05
|
||||
status: cancel
|
||||
priority: high
|
||||
state_hub_task_id: "4b178f15-bace-496d-8e59-efedd79e37be"
|
||||
```
|
||||
|
||||
Add database migration, uniqueness constraints, rollback, session security,
|
||||
logout, audit correlation, and railiance deployment configuration. Test Case A
|
||||
existing LLDAP user/JIT profile and Case B new registration/LLDAP creation,
|
||||
plus collisions, replay, concurrent callback, suspended identity, unlink,
|
||||
local-account coexistence, and step-up.
|
||||
|
||||
Done when both cases pass on the rebuilt coulomb.social application and local
|
||||
account rollback remains available.
|
||||
|
||||
2026-08-09: Cancelled before implementation because repository inspection
|
||||
found the Django consumer in the dedicated coulomb-social repository, where
|
||||
CSOC-WP-0002 already owns the NetKingdom shell. Successor: CSOC-WP-0003.
|
||||
Loading…
Add table
Add a link
Reference in a new issue