Name the account site NetKingdom Identity.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 40s
Account journey acceptance / journeys (push) Successful in 11s

Say "Signed in as" the identity, and describe a one-time code as a
higher security level of the NetKingdom sign-in rather than another
sign-in. The account site keeps its own session.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-26 23:48:00 +02:00
parent b5c60ab2bd
commit b987a3de9e
9 changed files with 50 additions and 39 deletions

View file

@ -22,8 +22,10 @@ class AccountAwarenessTests(unittest.TestCase):
def test_signed_out_home_states_only_the_portal_session(self):
_, body = invoke(self.app, "/", query="username=forged&tenant=tenant:evil:one")
self.assertIn(b"Login state", body)
self.assertIn(b"You are not signed in to this portal.", body)
self.assertIn(b"NetKingdom Identity", body)
self.assertIn(b"Identity", body)
self.assertIn(b"You are not signed in.", body)
self.assertIn(b"It is not another sign-in.", body)
self.assertNotIn(b"Active now", body)
self.assertNotIn(b"Allowed tenants", body)
self.assertNotIn(b"forged", body)
@ -45,7 +47,8 @@ class AccountAwarenessTests(unittest.TestCase):
self.assertIn(b"Workload decisions are not checked.", body)
self.assertNotIn(b"Viewing", body)
self.assertIn(b"An ordinary sign-in uses one tenant.", body)
self.assertIn(b"This is the portal session.", body)
self.assertIn(b"This session is for the account site.", body)
self.assertIn(b"Signed in as", body)
def test_allowed_tenant_that_is_not_active_uses_sign_in(self):
session = self.app.service.me(self.oidc.claims("member"), correlation_id="synthetic")