54 lines
3.1 KiB
Markdown
54 lines
3.1 KiB
Markdown
|
|
# Account clarity rollout — 2026-09-13
|
|||
|
|
|
|||
|
|
Source: user-engine a9ff77d21db5316d49d8d54519a490ca21951bc7.
|
|||
|
|
CI: user-engine image workflow run 133, success; CI smoke run 132, both jobs success.
|
|||
|
|
Image: `forgejo.coulomb.social/coulomb/user-engine@sha256:558e489f0b6e0b7160ab0d370560a66497e12488b95531bbccca122b46331a6f`.
|
|||
|
|
Runtime package pin: rapp-user-engine 367bb1b.
|
|||
|
|
|
|||
|
|
Applied an image-only JSON patch after checking cluster UID, deployment UID,
|
|||
|
|
resource version, predecessor digest and absent MFA management URL. The deployment
|
|||
|
|
rolled out successfully, Ready 1/1. Kept the existing Recreate strategy and resource
|
|||
|
|
requests; process-local portal sessions are invalidated on restart. No provider
|
|||
|
|
credential, OTP policy, enrollment setting, database or tenant membership changed.
|
|||
|
|
Unrelated hostname edits in the runtime package were preserved unstaged.
|
|||
|
|
|
|||
|
|
## Validation
|
|||
|
|
|
|||
|
|
- `PYTHONDONTWRITEBYTECODE=1 make test` in user-engine: 188 tests, 3 optional skips;
|
|||
|
|
layer conformance passed. Includes synthetic authenticated member/operator,
|
|||
|
|
expired/anonymous session controls, browser denial, API JSON, OTP handoff URL
|
|||
|
|
validation and untrusted recovery-parameter tests.
|
|||
|
|
- `PYTHONDONTWRITEBYTECODE=1 make check` in rapp-user-engine: 4 packaging tests passed.
|
|||
|
|
- `git diff --check` passed in both repositories.
|
|||
|
|
- Eight live HTTP assertions passed: anonymous home, recovery, logged-out and
|
|||
|
|
security controls/no-store; unavailable OTP setup without parameter spoofing;
|
|||
|
|
HTML browser denial; unchanged JSON API denial; readiness.
|
|||
|
|
- Twelve isolated Chromium assertions passed: public recovery, Sign in without
|
|||
|
|
portal logout, reachable identity switching, unavailable OTP setup, OTP-help
|
|||
|
|
return route, security page fitting a 390px viewport, HTML denial recovery,
|
|||
|
|
expired issuer callback stripping query parameters, shared sign-out confirmation,
|
|||
|
|
real browser POST through Authelia to portal, appropriate post-sign-out control,
|
|||
|
|
and truthful portal-session wording.
|
|||
|
|
|
|||
|
|
No header overrides, reused personal browser profile, actual account credentials,
|
|||
|
|
or OTP values were used. Anonymous browser checks do not prove authenticated
|
|||
|
|
identity switching or provider enrollment. Script copies are in the session's
|
|||
|
|
/tmp/account-clarity directory; durable acceptance cases are under tests/.
|
|||
|
|
|
|||
|
|
## Open acceptance
|
|||
|
|
|
|||
|
|
The provider factor-read credential remains rejected and its approved custody and
|
|||
|
|
renewal contract is unpublished. `USER_ENGINE_MFA_MANAGEMENT_URL` remains unset.
|
|||
|
|
The public help page does not claim OTP is off or enabled. Complete KEY-WP-0035
|
|||
|
|
and USER-WP-0027-T04 before enabling the provider handoff or optional live policy.
|
|||
|
|
|
|||
|
|
The 29 role-based journeys and their remaining implementation/acceptance gaps
|
|||
|
|
are in ../account-journeys.md. USER-WP-0027 stays active for T04–T06; authoritative
|
|||
|
|
workload discovery remains USER-WP-0026-T03. VERGABE-WP-0019 real-user acceptance
|
|||
|
|
remains open.
|
|||
|
|
|
|||
|
|
Rollback: CAS image-only replacement with the predecessor
|
|||
|
|
`sha256:8621032bacc3da5a4c8c96775422263d4b0cf775744126aa50c002b0a678ec5b`,
|
|||
|
|
then reconcile both runtime manifest and Makefile pins. This reverts the UI and
|
|||
|
|
restarts portal sessions; no database migration accompanied this release.
|