Record and pin verified account journey release
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-13 12:29:43 +02:00
parent 502a8e01d7
commit 62d6f8b0c7
7 changed files with 413 additions and 4 deletions

View file

@ -79,7 +79,7 @@ assurance claims, redirect return parameters or manual step completion.
```task
id: USER-WP-0027-T05
status: todo
status: progress
priority: high
state_hub_task_id: "92906113-e28b-58d3-95a7-779e815d1ced"
```
@ -94,7 +94,7 @@ are starting points, not browser acceptance. Split into owner workplans as neede
```task
id: USER-WP-0027-T06
status: todo
status: progress
priority: high
state_hub_task_id: "550886ca-f916-5637-9639-b4134b0da939"
```
@ -109,3 +109,5 @@ Record live evidence and hand off any residuals as live work before closing.
Implementation is split into USER-WP-0028 (user), USER-WP-0029 (tenant admin),
USER-WP-0030 (platform admin), and USER-WP-0031 (automated acceptance). These
are live workplans, not residuals parked only in the journey document.
Implemented admin journeys and automated suites are deployed; see docs/evidence/2026-09-13-journey-release.md and its machine-readable report. Full acceptance remains incomplete for the named integration/provider gaps.

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b"
---
Implements docs/account-journeys.md under USER-WP-0027. A passing local
@ -20,6 +21,7 @@ suite is not evidence that an external provider flow works live.
id: USER-WP-0028-T01
status: done
priority: high
state_hub_task_id: "baa9938e-271b-5590-bdc0-5c844070144c"
```
U01U04/U10U13: preserve safe profile input on validation failure; confirm saves, expose actual login name at password handoff, keep invitation/expired/session recovery reachable. Cover success, denial, provider interruption and retry.
@ -30,6 +32,7 @@ U01U04/U10U13: preserve safe profile input on validation failure; confirm
id: USER-WP-0028-T02
status: todo
priority: high
state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba"
```
U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment.
@ -40,6 +43,7 @@ U09 and T05: integrate a supported catalogue/admission source and scoped grants/
id: USER-WP-0028-T03
status: wait
priority: high
state_hub_task_id: "40e46e52-31ac-5abd-8793-04c1b7b82df3"
```
U05U08: depends on KEY-WP-0035 and NK-WP-0033 credential custody. Verify enrollment/cancel/replace/lost-factor recovery and old-AAL1-session behavior before enabling live handoff. No stub acceptance.

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
state_hub_workstream_id: "23963e14-255d-5935-b3d9-423e6f67f1d8"
---
Implements docs/account-journeys.md under USER-WP-0027. A passing local
@ -20,6 +21,7 @@ suite is not evidence that an external provider flow works live.
id: USER-WP-0029-T01
status: done
priority: high
state_hub_task_id: "c22c389c-0ee8-5f96-bd83-f584d29fce6e"
```
T01/T03/T04/T06: reject non-admin and wrong-tenant user IDs before provisioning/recovery/lifecycle calls; bind invitation operations to route tenant; protect shared identities from global tenant-scoped mutation.
@ -30,6 +32,7 @@ T01/T03/T04/T06: reject non-admin and wrong-tenant user IDs before provisioning/
id: USER-WP-0029-T02
status: done
priority: high
state_hub_task_id: "ce241cf7-b2fc-505c-a3e6-644ddb6689e9"
```
T06/T08: preview target/scope/action, CSRF-bound confirmation, reject stale state and last-admin removal, provide cancel and recovery. Keep domain/API guards as well as UI checks. Document concurrency/external propagation limits.
@ -40,6 +43,7 @@ T06/T08: preview target/scope/action, CSRF-bound confirmation, reject stale stat
id: USER-WP-0029-T03
status: done
priority: high
state_hub_task_id: "74664b6b-cc98-5332-a0d0-6a1a09a55556"
```
T02/T03/T04/T07: show actual directory login separately from display name, account state, provider uncertainty, invitation delivery status and appropriate next steps; prevent duplicate rows from workload memberships.

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
state_hub_workstream_id: "ab18c962-4ac4-5cf4-a8d9-edb773afbe8c"
---
Implements docs/account-journeys.md under USER-WP-0027. A passing local
@ -20,6 +21,7 @@ suite is not evidence that an external provider flow works live.
id: USER-WP-0030-T01
status: done
priority: high
state_hub_task_id: "f51e3796-b649-586b-a228-c23f94804500"
```
P01/P03/P05/P08/T08: authorized browser views of safe audit metadata and delivery state, reference filtering, CSRF replay with readback, no raw payload/credential/error dumps.
@ -30,6 +32,7 @@ P01/P03/P05/P08/T08: authorized browser views of safe audit metadata and deliver
id: USER-WP-0030-T02
status: done
priority: high
state_hub_task_id: "09c2d30a-8230-5da2-b2d4-7a161259f557"
```
P02/P04/P07: preserve first-admin setup on retry without duplication, explicit tenant lifecycle confirmation, stale-version recovery and validation; verify cross-role isolation.
@ -40,6 +43,7 @@ P02/P04/P07: preserve first-admin setup on retry without duplication, explicit t
id: USER-WP-0030-T03
status: wait
priority: high
state_hub_task_id: "07510026-caee-54d7-998c-a8d2b2f17773"
```
P04P06: owner-approved factor credential delivery/renewal and provider recovery/policy control. Depends on KEY-WP-0035/NK-WP-0033; no secret vending through portal or chat.

View file

@ -4,11 +4,12 @@ type: workplan
title: "Automated user and administrator journey suites"
domain: communication
repo: user-engine
status: active
status: finished
owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
state_hub_workstream_id: "3579f6bb-464e-506f-870c-e4e1b73c161c"
---
Implements docs/account-journeys.md under USER-WP-0027. A passing local
@ -20,6 +21,7 @@ suite is not evidence that an external provider flow works live.
id: USER-WP-0031-T01
status: done
priority: high
state_hub_task_id: "7243f931-32c8-585a-b9a4-decb6f35fd57"
```
Run synthetic identities through actual WSGI routes and domain stores, with controlled provider failure/retry fixtures. Assert success, denial, unchanged state on failure, recovery and tenant isolation. Add make test-journeys and CI execution.
@ -30,6 +32,7 @@ Run synthetic identities through actual WSGI routes and domain stores, with cont
id: USER-WP-0031-T02
status: done
priority: high
state_hub_task_id: "fd222e7c-00c9-525c-b09d-d5851277f011"
```
Map every journey to real tests and explicit external acceptance blockers. Report missing live acceptance as incomplete, never a passing placeholder. Keep matrix/workplans synchronized.
@ -38,8 +41,9 @@ Map every journey to real tests and explicit external acceptance blockers. Repor
```task
id: USER-WP-0031-T03
status: progress
status: done
priority: high
state_hub_task_id: "3b04c187-a69d-5c30-b73d-ae36792d4d04"
```
Run full unit/conformance suites and live read-only smoke, deploy digest-pinned reviewed source with CAS and rollback evidence. Retain provider-dependent journeys as live tasks until external acceptance passes.
@ -49,3 +53,5 @@ Validation: 210 database-enabled regression tests passed with no skips,
including independent-connection last-admin protection and nested bootstrap
rollback. Thirteen isolated Chromium checks passed. Provider OTP and application
access integration remain explicitly open; no complete-journey claim is inferred.
Release evidence: docs/evidence/2026-09-13-journey-release.md. Residual integration and live acceptance remain in USER-WP-0028-T02/T03, USER-WP-0030-T03 and USER-WP-0027-T06; these live records precede closure.