Close recovery acceptance and reconcile blocked workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Account journey acceptance / journeys (push) Successful in 10s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e38e-e5bb-7b50-968d-a738a0294997
This commit is contained in:
tegwick 2026-09-27 17:54:47 +02:00
parent b73f553c18
commit eca7c54748
9 changed files with 162 additions and 46 deletions

View file

@ -4,12 +4,12 @@ type: workplan
title: "Account recovery and visible identity and access"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: user-engine
created: "2026-09-12"
updated: "2026-09-12"
updated: "2026-09-27"
state_hub_workstream_id: "0aea0a52-13f9-515b-bda8-665f8a4f2d5e"
---
@ -37,7 +37,7 @@ MFA downgrade, global JWT revocation claim or inferred workload entitlements.
```task
id: USER-WP-0026-T02
status: progress
status: done
priority: high
state_hub_task_id: "ad5b0a77-d8ec-5e07-9a9e-2fa231a6f792"
```
@ -49,11 +49,19 @@ logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06.
Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress.
2026-09-27: closed against the completed release and attended owner evidence.
The 2026-09-12 release receipt is supplemented by
`key-cape/docs/evidence/2026-09-24-fresh-login-and-account-switch.md`:
the founder confirmed fresh login and account switching, and the issuer recorded
three fresh portal authentication/token-issuance sequences after an MFA failure.
KEY-WP-0034-T02 is done. Existing application JWTs may still outlive provider
logout. This does not accept the remaining multi-user Vergabe pilot.
## Discover workload access from authoritative application records
```task
id: USER-WP-0026-T03
status: todo
status: wait
priority: high
state_hub_task_id: "95e9a6d4-7e57-5483-97c5-3f4a45bb6767"
```
@ -74,3 +82,11 @@ checks and six fresh anonymous Chromium checks pass, including actual provider
logout POST and return to the portal without test overrides. Real-user identity
switching is still awaiting operator evidence; no authenticated/MFA acceptance
is inferred. Detailed receipt: railiance-apps/docs/evidence/2026-09-12-account-recovery-live.md.
2026-09-27: blocked on an owner-supported workload catalogue/admission and
scoped grant/revocation contract. The access-engine policy evaluator and local
user-engine application/membership records do not establish that contract.
Need registered HTTPS entry points, exact identity/tenant/action mapping,
authoritative allow/deny/unavailable results, and scoped mutation/readback
semantics from the application and authorization owners. Continues jointly with
USER-WP-0028-T02; no local grant inference or substitute catalogue was added.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Clear account state and complete user, tenant-admin and platform-admin journeys"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-22"
updated: "2026-09-27"
state_hub_workstream_id: "455300ca-ec1e-569e-a584-a8dcda2595cf"
---
@ -76,6 +76,18 @@ recovery and fresh login; resolve privileged portal policy. Only then configure
USER_ENGINE_MFA_MANAGEMENT_URL and accept U05–U08/P04–P06. Do not fake a status from
assurance claims, redirect return parameters or manual step completion.
2026-09-27: the missing credential/policy blocker above is superseded.
KEY-WP-0035 finished on September 14; RPF-WP-0040 delivered the renewable
factor-reader lane. NK-WP-0033 closed its separate historical incident on
September 23. P04 recovery and P06 optional policy are implemented and deployed;
see `docs/evidence/2026-09-13-p04-recovery.md` and
`docs/evidence/2026-09-13-p06-authentication-policy.md`.
Installed-provider fixtures prove activation, cancellation, old-session MFA and
recovery/replacement; they do not prove a real invited person's full OTP journey.
Remaining gate: attended U05–U08 enrollment/cancel/replacement/lost-factor and
fresh-login acceptance, plus verified portal setup handoff configuration. No new
credential request is required to resolve the historical blocker.
## Close tenant and platform administrator usability gaps
```task
@ -103,7 +115,7 @@ It does not accept those journeys.
```task
id: USER-WP-0027-T06
status: progress
status: wait
priority: high
state_hub_task_id: "550886ca-f916-5637-9639-b4134b0da939"
```
@ -120,3 +132,11 @@ USER-WP-0030 (platform admin), and USER-WP-0031 (automated acceptance). These
are live workplans, not residuals parked only in the journey document.
Implemented admin journeys and automated suites are deployed; see docs/evidence/2026-09-13-journey-release.md and its machine-readable report. Full acceptance remains incomplete for the named integration/provider gaps.
2026-09-27: blocked on the remaining acceptance dependencies, not ongoing
local implementation. USER-WP-0026-T02 now closes account-switch verification.
USER-WP-0035-T02 retains setup-link delivery; USER-WP-0028-T03 retains actual
OTP journeys; USER-WP-0026-T03/USER-WP-0028-T02 retain authoritative workload
access. VERGABE-WP-0019-T06 still needs the second user and setup-to-workflow
acceptance. Automated coverage remains an implementation check, not full live
acceptance. See `docs/evidence/2026-09-27-loose-ends-review.md`.

View file

@ -4,12 +4,12 @@ type: workplan
title: "User account journeys and recovery"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: communication
created: "2026-09-13"
updated: "2026-09-13"
updated: "2026-09-27"
state_hub_workstream_id: "145df9d5-a7e9-5d20-8280-9d3ea069838b"
---
@ -31,13 +31,19 @@ U01–U04/U10–U13: preserve safe profile input on validation failure; confirm
```task
id: USER-WP-0028-T02
status: todo
status: wait
priority: high
state_hub_task_id: "5d1bf977-034d-5448-b4fb-5a8b630af6ba"
```
U09 and T05: integrate a supported catalogue/admission source and scoped grants/revocation. Do not present static links or membership as effective authorization. Continues USER-WP-0026-T03; establish provider contract before deployment.
2026-09-27: blocked on the provider-owned catalogue/admission and scoped
application grant/revocation contract described in USER-WP-0026-T03. Current
membership CRUD and PDP evaluation cannot supply fleet-wide admission or mutate
application-owned grants. Resume integration after owners identify the supported
source, entry-point registry, identity/action mapping and mutation contract.
## Complete optional OTP onboarding with provider evidence
```task
@ -54,3 +60,11 @@ Validation: 210 database-enabled regression tests passed with no skips,
including independent-connection last-admin protection and nested bootstrap
rollback. Thirteen isolated Chromium checks passed. Provider OTP and application
access integration remain explicitly open; no complete-journey claim is inferred.
2026-09-27: credential custody and optional-policy rollout are complete
(KEY-WP-0035, RPF-WP-0040); NK-WP-0033 is also finished. The earlier missing-
credential dependency is superseded. P04/P06 installed-provider evidence covers
enrollment/cancellation, recovery/replacement and old-session enforcement.
The remaining blocker is attended real-user U05–U08 acceptance and verified
portal setup handoff, not another service token. See USER-WP-0027-T04 and
`docs/evidence/2026-09-13-p06-authentication-policy.md`.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Follow the flex-auth to access-engine repository rename (FLEX-WP-0020 handoff)"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: claude-code
topic_slug: user-engine
created: "2026-09-22"
updated: "2026-09-22"
updated: "2026-09-27"
related: [FLEX-WP-0020]
state_hub_workstream_id: "0b948be1-ad75-5548-b4eb-aabc8e3ae6cc"
---
@ -53,3 +53,9 @@ registered. Then change `wiki/ArchitectureBlueprint.md:14` from
access-engine path, confirm the target file exists there, and reply on the
FLEX-WP-0020 handoff thread with the commit. Leave historical workplans and
evidence unchanged.
2026-09-27: rechecked the owner workplan and filesystem. FLEX-WP-0020 §8
remains wait; `/home/worsch/access-engine` does not exist, while
`/home/worsch/flex-auth/docs/iam-profile-consumption.md` remains present.
The existing reference is still correct. Blocked until the renamed canonical
checkout is registered; runtime vocabulary remains unchanged.

View file

@ -4,12 +4,12 @@ type: workplan
title: "Onboarding handoff findings from the 2026-09-23 operator run"
domain: communication
repo: user-engine
status: active
status: blocked
flavor: implementation
owner: claude-code
topic_slug: user-engine
created: "2026-09-23"
updated: "2026-09-23"
updated: "2026-09-27"
related: [USER-WP-0027, USER-WP-0028, NK-WP-0036, NK-WP-0041]
state_hub_workstream_id: "35aa6adf-255a-5705-9294-a50d98e45f00"
---
@ -60,3 +60,12 @@ governed transactional mail lane (`email-connect` plus the OpenBao delivery
token) that SCOPE records as operator-owned; U04 and T02 in
`tests/journey-coverage.json` stay `external-blocked` until then. Do not
substitute a portal-rendered link for delivery evidence.
2026-09-27: the generic missing-mail-lane description above is superseded
by EMAIL-WP-0004 and USER-WP-0032/P05: the authenticated mail lane exists and
live non-sending SMTP/store checks passed. That adapter handles invitation
outbox events, not the provider's single-use password-setup link. Closing this
task still needs an owner-supported setup-link delivery handoff and evidence of
receipt by the intended person; a generic SMTP success is insufficient.
The latest attended onboarding record still uses out-of-band handoff. No message
was sent and no setup-link secret was copied into an event or work record.