Record Binky MFA journey feedback
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-29 22:05:24 +02:00
parent 53d38f2f1e
commit 0d1c7e133a

View file

@ -189,6 +189,14 @@ registration, directory login, replay denial, and cleanup. Remaining Binky
acceptance is the human-selected password, MFA enrollment, and tenant
claim/denial evidence; no one-shot operator password was used.
2026-07-29 human acceptance: `bernd.worsch` completed the portal-issued
password setup, privacyIDEA TOTP enrollment, and a fresh KeyCape
password-plus-OTP login. Two UX follow-ups were captured from the live journey:
accept/display the email alias instead of requiring the directory uid wherever
the provider permits, and make authenticator labels identify the account.
privacyIDEA's future enrollment label is now `Coulomb: {user}@{realm}` at the
otpauth issuer/account level; existing wallet entries require a local rename.
## T08 - Closure and next-stage handoff
```task