Name the account site NetKingdom Identity.
Say "Signed in as" the identity, and describe a one-time code as a higher security level of the NetKingdom sign-in rather than another sign-in. The account site keeps its own session. Assistant: grok Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
parent
b5c60ab2bd
commit
b987a3de9e
9 changed files with 50 additions and 39 deletions
|
|
@ -9,9 +9,11 @@ headless capability alone does not mean a journey is usable or verified live.
|
|||
|
||||
## Common interaction rules
|
||||
|
||||
- The header states the verified portal identity, or “Not signed in to this
|
||||
portal.” A valid portal session shows Log out; an absent/expired session shows
|
||||
Sign in. Never infer identity from URL parameters or an existing provider tab.
|
||||
- The header is titled NetKingdom Identity. It states “Signed in as” the
|
||||
verified identity, or “Not signed in.” A valid account-site session shows
|
||||
Log out; an absent or expired session shows Sign in. A one-time code raises
|
||||
the security level of the NetKingdom sign-in and is not another sign-in.
|
||||
Never infer identity from URL parameters or an existing provider tab.
|
||||
- The portal cannot observe every application or shared-provider session. Explain
|
||||
this once in sign-out confirmation or expandable identity-switch help, not as
|
||||
competing login/logout actions everywhere. “Use another account” remains
|
||||
|
|
@ -34,7 +36,7 @@ headless capability alone does not mean a journey is usable or verified live.
|
|||
|
||||
| ID / intent | Success | Failure and recovery | Current support / acceptance |
|
||||
|---|---|---|---|
|
||||
| U01 — Know whether I am signed in | Header and the home page name the verified portal identity, or say the portal session is absent. An application may keep its own session | Expired/unknown cookie shows signed-out state; a query does not invent a session; sign in again | Implemented; automated anonymous/expired/member/operator tests, including the home login-state section |
|
||||
| U01 — Know whether I am signed in | Header and the home page say “Signed in as” the verified identity, or that no account-site session exists. An application may keep its own session. A one-time code is a higher security level, not another sign-in | Expired/unknown cookie shows signed-out state; a query does not invent a session; sign in again | Implemented; automated anonymous/expired/member/operator tests, including the home identity section |
|
||||
| U02 — Sign in to my company application | Personal login lands in the intended tenant and application | Wrong credentials stay on provider; denied membership leads to account help with identity switching | Recovery deployed previously; actual fresh-user acceptance waiting on OTP |
|
||||
| U03 — Accept an invitation | Confirm intended tenant/role, accept once, then see next setup step | Expired/used/wrong-person invitation explains next step; admin reissues without duplicates | Service/browser routes exist; live delivery and full browser acceptance pending |
|
||||
| U04 — Set or recover my password | Use actual login name, complete single-use setup, return to sign-in | Missing mail or expired link offers admin-assisted new setup link | Password setup reported successful; login name and sign-in address now named at handoff and in the user entry (2026-09-23 run, USER-WP-0035-T01); email delivery unresolved (USER-WP-0035-T02) |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue