Show an existing NetKingdom sign-in before the account site continues it.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 19s
Account journey acceptance / journeys (push) Successful in 8s

The account site said "Not signed in" while Authelia still had a session, and Sign in reused that identity. Ask Authelia who the session cookie is, show that name, and send a fresh sign-in only when a different identity is requested.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-27 00:21:34 +02:00
parent b987a3de9e
commit 560cdeed46
9 changed files with 500 additions and 19 deletions

View file

@ -9,11 +9,17 @@ headless capability alone does not mean a journey is usable or verified live.
## Common interaction rules
- The header is titled NetKingdom Identity. It states “Signed in as” the
verified identity, or “Not signed in.” A valid account-site session shows
Log out; an absent or expired session shows Sign in. A one-time code raises
the security level of the NetKingdom sign-in and is not another sign-in.
Never infer identity from URL parameters or an existing provider tab.
- The header is titled NetKingdom Identity. An account-site session says
“Signed in as” the verified identity and offers Log out. With no account-site
session, the header says “Not signed in” and offers Sign in. When the browser
already sent a NetKingdom session cookie, the account site asks the sign-in
service which identity that cookie is and shows “NetKingdom sign-in is” that
confirmed name, with “This account site has no session yet.” Continue reuses
that identity. “Use a different identity” starts a fresh NetKingdom sign-in.
A URL parameter does not name the visitor. If the sign-in service does not
answer, the page stays “Not signed in” and does not invent a name. A one-time
code raises the security level of the NetKingdom sign-in and is not another
sign-in.
- The portal cannot observe every application or shared-provider session. Explain
this once in sign-out confirmation or expandable identity-switch help, not as
competing login/logout actions everywhere. “Use another account” remains
@ -36,7 +42,7 @@ headless capability alone does not mean a journey is usable or verified live.
| ID / intent | Success | Failure and recovery | Current support / acceptance |
|---|---|---|---|
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity, or that no account-site session exists. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; sign in again | Implemented; automated anonymous/expired/member/operator tests, including the home identity section |
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity when an account-site session exists. With no account-site session they say “Not signed in,” unless the sign-in service confirms an existing NetKingdom identity, which is then named before the account site continues. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; a failed identity lookup stays signed out; sign in again, or use a different identity | Implemented; automated anonymous/expired/member/operator tests, including the home identity section and a confirmed NetKingdom sign-in with no account-site session |
| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Recovery deployed previously; actual fresh-user acceptance waiting on OTP |
| U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending |
| U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) |