diff --git a/workplans/KEY-WP-0033-vergabe-fresh-login.md b/workplans/KEY-WP-0033-vergabe-fresh-login.md index ff3dc72..8099b4f 100644 --- a/workplans/KEY-WP-0033-vergabe-fresh-login.md +++ b/workplans/KEY-WP-0033-vergabe-fresh-login.md @@ -33,8 +33,7 @@ contains four service clients and the admitted human approver client. ```task id: KEY-WP-0033-T02 -status: wait -blocking_reason: "Release prepared; await the documented attended shared-KeyCape rollout." +status: progress priority: high state_hub_task_id: "7b58f08c-6063-554a-8700-a1edbc805ca4" ``` @@ -54,3 +53,18 @@ digest sha256:5f10f36a5da23ce1aaf3df9b84a8ff98d7926f34ceaa19e63bd3356adb68e01a. The exact client-registration and deployment server dry runs pass. The runtime is unchanged. Await the attended window required by docs/operations.md; the complete packet is railiance-apps/docs/vergabe-demo-company-sso-rollout.md. + +2026-09-12 attended rollout executed after explicit operator approval. KeyCape +and password setup are Ready on the prepared digests; exact public client +registration was CAS-applied (config resourceVersion 60123977) with unrelated +config bytes/Secret data preserved. Existing portal and product client both +pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks). +Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain, +and requests remain 60m CPU/256Mi memory. Eleven live product checks pass: +company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only +login start, native issuer redirect, private company/media protection and +invalid callback/confirmation rejection. Initial readback showed zero accounts, +identity mappings and staff accounts. Native invited-user sign-in/MFA and +confirmation are now requested from the operator; no user credential was used +by the agent. Recovery and two-user acceptance remain their existing tasks. +Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.