Show an existing NetKingdom sign-in before the account site continues it.
The account site said "Not signed in" while Authelia still had a session, and Sign in reused that identity. Ask Authelia who the session cookie is, show that name, and send a fresh sign-in only when a different identity is requested. Assistant: grok Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
parent
b987a3de9e
commit
560cdeed46
9 changed files with 500 additions and 19 deletions
|
|
@ -9,11 +9,17 @@ headless capability alone does not mean a journey is usable or verified live.
|
|||
|
||||
## Common interaction rules
|
||||
|
||||
- The header is titled NetKingdom Identity. It states “Signed in as” the
|
||||
verified identity, or “Not signed in.” A valid account-site session shows
|
||||
Log out; an absent or expired session shows Sign in. A one-time code raises
|
||||
the security level of the NetKingdom sign-in and is not another sign-in.
|
||||
Never infer identity from URL parameters or an existing provider tab.
|
||||
- The header is titled NetKingdom Identity. An account-site session says
|
||||
“Signed in as” the verified identity and offers Log out. With no account-site
|
||||
session, the header says “Not signed in” and offers Sign in. When the browser
|
||||
already sent a NetKingdom session cookie, the account site asks the sign-in
|
||||
service which identity that cookie is and shows “NetKingdom sign-in is” that
|
||||
confirmed name, with “This account site has no session yet.” Continue reuses
|
||||
that identity. “Use a different identity” starts a fresh NetKingdom sign-in.
|
||||
A URL parameter does not name the visitor. If the sign-in service does not
|
||||
answer, the page stays “Not signed in” and does not invent a name. A one-time
|
||||
code raises the security level of the NetKingdom sign-in and is not another
|
||||
sign-in.
|
||||
- The portal cannot observe every application or shared-provider session. Explain
|
||||
this once in sign-out confirmation or expandable identity-switch help, not as
|
||||
competing login/logout actions everywhere. “Use another account” remains
|
||||
|
|
@ -36,7 +42,7 @@ headless capability alone does not mean a journey is usable or verified live.
|
|||
|
||||
| ID / intent | Success | Failure and recovery | Current support / acceptance |
|
||||
|---|---|---|---|
|
||||
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity, or that no account-site session exists. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; sign in again | Implemented; automated anonymous/expired/member/operator tests, including the home identity section |
|
||||
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity when an account-site session exists. With no account-site session they say “Not signed in,” unless the sign-in service confirms an existing NetKingdom identity, which is then named before the account site continues. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; a failed identity lookup stays signed out; sign in again, or use a different identity | Implemented; automated anonymous/expired/member/operator tests, including the home identity section and a confirmed NetKingdom sign-in with no account-site session |
|
||||
| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Recovery deployed previously; actual fresh-user acceptance waiting on OTP |
|
||||
| U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending |
|
||||
| U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue