113 lines
3.7 KiB
Markdown
113 lines
3.7 KiB
Markdown
---
|
|
id: HF-WP-0004
|
|
type: workplan
|
|
title: "Integrate coulomb.social with NetKingdom login and JIT profiles"
|
|
domain: infotech
|
|
repo: helix-forge
|
|
status: archived
|
|
owner: codex
|
|
topic_slug: netkingdom
|
|
created: "2026-08-09"
|
|
updated: "2026-08-09"
|
|
depends_on:
|
|
- NK-WP-0025
|
|
- USER-WP-0022
|
|
- KEY-WP-0008
|
|
state_hub_workstream_id: "ba123393-fccc-48a0-a228-b7d0aa2fd663"
|
|
---
|
|
|
|
# HF-WP-0004 - coulomb.social login and first-login profile
|
|
|
|
Add NetKingdom OIDC as an alternative to coulomb.social local registration.
|
|
The application keeps ownership of its local profile and authorization while
|
|
using KeyCape for authentication.
|
|
|
|
## T01 - Pin the OIDC consumer and account-link contract
|
|
|
|
```task
|
|
id: HF-WP-0004-T01
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "71db76f0-8842-4e00-a314-ee26669e2ce3"
|
|
```
|
|
|
|
Implement authorization-code plus PKCE against the existing coulomb-social
|
|
KeyCape client and exact production callback. Store the stable issuer/subject
|
|
link separately from username and email. Define explicit handling for an
|
|
existing local account whose verified email matches the OIDC identity.
|
|
|
|
Done when email matching cannot silently attach or replace an existing local
|
|
account.
|
|
|
|
## T02 - Create the profile idempotently on first login
|
|
|
|
```task
|
|
id: HF-WP-0004-T02
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "34d0c78a-08db-49a8-8f5c-71f9a5c15dce"
|
|
```
|
|
|
|
On a valid callback, atomically find-or-create the coulomb.social application
|
|
profile keyed by issuer/subject, seed ordinary-user defaults, establish the
|
|
application session, and redirect to the intended page. Repeated callbacks,
|
|
concurrent tabs, and retries must return the same profile.
|
|
|
|
Done when an existing LLDAP user with no application profile can sign in and
|
|
receive exactly one regular coulomb.social profile.
|
|
|
|
## T03 - Add login and registration choices
|
|
|
|
```task
|
|
id: HF-WP-0004-T03
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "6b33b969-3fad-4579-abc5-0bc3856d12cc"
|
|
```
|
|
|
|
Offer Sign in with NetKingdom, Create NetKingdom account, and the existing
|
|
local-account path according to product policy. The registration choice uses
|
|
the signed return flow from NK-WP-0025; completion starts a fresh OIDC login.
|
|
Avoid user enumeration and open redirects.
|
|
|
|
Done when a completely new person can register from the coulomb.social
|
|
landing page and return as an authenticated regular user.
|
|
|
|
## T04 - Enforce profile/action assurance
|
|
|
|
```task
|
|
id: HF-WP-0004-T04
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "4fc5253a-f485-4259-8cea-ed0968f958e5"
|
|
```
|
|
|
|
Accept password-level assurance for ordinary profiles unless the application
|
|
profile or requested action requires MFA. For step-up, send a fresh KeyCape
|
|
authorization request and verify the returned assurance before completing the
|
|
action. Never infer MFA from email or application session age alone.
|
|
|
|
Done when the attended tegwick profile works without MFA by default and can
|
|
be configured to require MFA without changing another user's profile.
|
|
|
|
## T05 - Migrate, deploy, and prove both cases
|
|
|
|
```task
|
|
id: HF-WP-0004-T05
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "4b178f15-bace-496d-8e59-efedd79e37be"
|
|
```
|
|
|
|
Add database migration, uniqueness constraints, rollback, session security,
|
|
logout, audit correlation, and railiance deployment configuration. Test Case A
|
|
existing LLDAP user/JIT profile and Case B new registration/LLDAP creation,
|
|
plus collisions, replay, concurrent callback, suspended identity, unlink,
|
|
local-account coexistence, and step-up.
|
|
|
|
Done when both cases pass on the rebuilt coulomb.social application and local
|
|
account rollback remains available.
|
|
|
|
2026-08-09: Cancelled before implementation because repository inspection
|
|
found the Django consumer in the dedicated coulomb-social repository, where
|
|
CSOC-WP-0002 already owns the NetKingdom shell. Successor: CSOC-WP-0003.
|