key-cape/workplans/KEY-WP-0034-account-recovery.md
tegwick 074c2ce498
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 44s
Add central login recovery and confirmed shared sign-out
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:34:41 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated
KEY-WP-0034 workplan Browser authentication recovery and confirmed shared sign-out infotech key-cape active codex key-cape 2026-09-12 2026-09-12

The operator reports a dead-end authentication error after using an account outside the product tenant. Recent issuer telemetry indicates token exchange failure; tenant rejection and provider failure must not be conflated.

Implement and validate recovery

id: KEY-WP-0034-T01
status: done
priority: high

Route failed browser login to the public account recovery surface without codes, state or unverified identity. Show verified portal identity, tenant memberships, and recorded workload memberships; preserve operator/customer separation. Provide CSRF-protected portal logout and confirmed shared provider sign-out with fixed owner-configured return locations. No automatic reauthentication loops, MFA downgrade, global JWT revocation claim or inferred workload entitlements.

Publish and verify the recovery flow

id: KEY-WP-0034-T02
status: progress
priority: high

Publish immutable images, update canonical runtime pins, verify anonymous recovery and sign-out confirmation live, and record actual account switching only after browser evidence. Existing application sessions may outlive provider logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06.

Source verification: Full Go suite passed; final OIDC/config tests passed after recovery expansion. Immutable publication and live checks are in progress.