Record tenant administration UI evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-28 01:32:25 +02:00
parent e23674d343
commit 5a4a908427

View file

@ -106,6 +106,14 @@ inspect cross-tenant lifecycle gaps, and perform explicitly authorized
recovery actions. Prove ordinary users and tenant admins cannot reach recovery actions. Prove ordinary users and tenant admins cannot reach
platform or other-tenant data. platform or other-tenant data.
2026-07-28 implementation evidence: the deployed admin surface lists
tenant-scoped members, creates the user and approved role as a separate
auditable step, provisions the login through the provider-neutral adapter,
persists the external subject link, and suspends/reactivates both LLDAP login
and the tenant account. Browser mutations require an OIDC session and
per-session CSRF token. Platform tenant creation, invitation/recovery breadth,
removal, and full cross-tenant conformance remain.
## T05 - Add production persistence and operability ## T05 - Add production persistence and operability
```task ```task
@ -142,6 +150,9 @@ proved first create, replay/resume, tenant group projection, and cleanup through
the restricted deployment path. The complete browser, authorization, failure, the restricted deployment path. The complete browser, authorization, failure,
accessibility, and restore matrix remains. accessibility, and restore matrix remains.
The admin increment adds explicit regression coverage for missing/wrong CSRF,
required API idempotency, provider-link persistence, and suspension calls.
## T07 - Binky production acceptance ## T07 - Binky production acceptance
```task ```task