Show an existing NetKingdom sign-in before the account site continues it.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 19s
Account journey acceptance / journeys (push) Successful in 8s

The account site said "Not signed in" while Authelia still had a session, and Sign in reused that identity. Ask Authelia who the session cookie is, show that name, and send a fresh sign-in only when a different identity is requested.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-27 00:21:34 +02:00
parent b987a3de9e
commit 560cdeed46
9 changed files with 500 additions and 19 deletions

View file

@ -72,6 +72,14 @@ non_tooling_clients:
write: false
note: Consumes identity claims as PIP input. Not a key-cape admin client.
- id: netkingdom-sign-in-state
target: key-cape
layer: tooling-as-claim-input
module: src/user_engine/identity_state.py
operation: "GET Authelia /api/state for the username on the session cookie the browser already sent"
write: false
note: Names an existing NetKingdom sign-in. Does not create an account-site session and is not an authorization decision.
- id: env-injected-secrets
target: Railiance secret injection
layer: not-catalogued