Name the account site NetKingdom Identity.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 40s
Account journey acceptance / journeys (push) Successful in 11s

Say "Signed in as" the identity, and describe a one-time code as a
higher security level of the NetKingdom sign-in rather than another
sign-in. The account site keeps its own session.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-26 23:48:00 +02:00
parent b5c60ab2bd
commit b987a3de9e
9 changed files with 50 additions and 39 deletions

View file

@ -22,8 +22,10 @@ class AccountAwarenessTests(unittest.TestCase):
def test_signed_out_home_states_only_the_portal_session(self):
_, body = invoke(self.app, "/", query="username=forged&tenant=tenant:evil:one")
self.assertIn(b"Login state", body)
self.assertIn(b"You are not signed in to this portal.", body)
self.assertIn(b"NetKingdom Identity", body)
self.assertIn(b"Identity", body)
self.assertIn(b"You are not signed in.", body)
self.assertIn(b"It is not another sign-in.", body)
self.assertNotIn(b"Active now", body)
self.assertNotIn(b"Allowed tenants", body)
self.assertNotIn(b"forged", body)
@ -45,7 +47,8 @@ class AccountAwarenessTests(unittest.TestCase):
self.assertIn(b"Workload decisions are not checked.", body)
self.assertNotIn(b"Viewing", body)
self.assertIn(b"An ordinary sign-in uses one tenant.", body)
self.assertIn(b"This is the portal session.", body)
self.assertIn(b"This session is for the account site.", body)
self.assertIn(b"Signed in as", body)
def test_allowed_tenant_that_is_not_active_uses_sign_in(self):
session = self.app.service.me(self.oidc.claims("member"), correlation_id="synthetic")

View file

@ -17,7 +17,7 @@ class AccountClarityTests(unittest.TestCase):
self.assertIn(b'href="/login">Sign in', body)
self.assertNotIn(b'href="/logout"', body)
self.assertNotIn(b'action="/logout"', body)
self.assertNotIn(b'Signed in to this portal as', body)
self.assertNotIn(b'Signed in as', body)
self.assertNotIn(b'You have logged out', body)
self.assertEqual('no-store', response['headers']['Cache-Control'])
@ -27,7 +27,7 @@ class AccountClarityTests(unittest.TestCase):
with self.subTest(path=path, who=who):
response, body = invoke(self.app, path, cookie='ue_session='+who)
self.assertEqual('200 OK', response['status'])
self.assertIn(b'Signed in to this portal as', body)
self.assertIn(b'Signed in as', body)
self.assertIn(b'href="/logout"', body)
self.assertNotIn(b'href="/login"', body)
self.assertNotIn(b'Verify my current identity', body)

View file

@ -17,9 +17,9 @@ class AccountRecoveryTests(unittest.TestCase):
response, body = self.get('/access-recovery')
self.assertEqual('200 OK', response['status'])
self.assertIn(b'/onboarding', body)
self.assertIn(b'This portal is signed in as', body)
self.assertIn(b'Signed in as', body)
_, body = self.get('/onboarding')
self.assertIn(b'Login state', body)
self.assertIn(b'Identity', body)
self.assertIn(b'Allowed workloads', body)
self.assertIn(b'No workload access is recorded.', body)
self.assertIn(b'Workload decisions are not checked.', body)

View file

@ -42,7 +42,7 @@ class AuthenticationPolicyJourney(JourneyFixture):
self.assertEqual('403 Forbidden',response['status'])
self.oidc.sessions['operator'].claims['assurance']['at']=time.time()-301
_,body=invoke(self.app,'/platform/authentication-policy',cookie='ue_session=operator')
self.assertIn(b'fresh MFA sign-in',body);self.assertEqual([],self.provider.calls)
self.assertIn(b'one-time code before viewing',body);self.assertEqual([],self.provider.calls)
def test_review_explains_lockout_scope_rollback_and_receipts(self):
_,body=self.post('/platform/authentication-policy',who='operator',action='preview',client='vergabe-demo-company',mode='mandatory',reference='p06-case')
self.assertIn(b'Review policy change',body);self.assertIn(b'unable to complete sign-in',body)

View file

@ -74,6 +74,6 @@ class PlatformSupportJourneys(JourneyFixture):
response,body=invoke(self.app,"/platform/operations",cookie="ue_session=operator")
self.assertEqual("200 OK",response["status"])
self.assertIn(b"Configured; live health unverified",body)
self.assertIn(b"Unavailable in this portal",body)
self.assertIn(b"Unavailable on this account site",body)
self.assertIn(b"assisted password setup",body)
self.assertIn(b"Review authentication policy",body)

View file

@ -103,7 +103,7 @@ class PortalNavigationTests(unittest.TestCase):
def test_get_logout_only_confirms_and_bad_csrf_does_not_end_session(self):
response, body = self.get('/logout')
self.assertEqual('200 OK',response['status'])
self.assertIn(b'Log out of this portal?',body)
self.assertIn(b'End this account-site session?',body)
self.assertIsNotNone(self.oidc.claims('operator'))
for token in ['', 'wrong', 'member-csrf']:
response,_=invoke(self.app,'/logout',method='POST',cookie='ue_session=operator',form={'csrf_token':token})