user-engine/workplans/USER-WP-0033-authentication-policy.md
tegwick 3bd1827a7f
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Build and Publish Container Image / build-and-push (push) Successful in 51s
Account journey acceptance / journeys (push) Successful in 7s
Implement scoped P06 authentication policy and guarded optional onboarding
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:00:07 +02:00

2.3 KiB

id type title domain repo status owner topic_slug created updated
USER-WP-0033 workplan P06 scoped authentication policy and safe optional onboarding communication user-engine active codex communication 2026-09-13 2026-09-13

Implements P06 under USER-WP-0030-T03 and KEY-WP-0035. Authorized by the user's P06 request and prior optional-OTP requirement. Existing MFA enforcement for unrelated clients remains in its current configuration.

Protect privileged actions independently of ordinary account login

id: USER-WP-0033-T01
status: done
priority: high

AAL1 users can reach account/onboarding and authenticator setup. Administrative browser/API operations require MFA. Policy changes and factor recovery require recent MFA. Explain step-up, unavailable setup and identity-switch recovery.

Provide scoped policy preview, confirmed apply, audit and rollback

id: USER-WP-0033-T02
status: done
priority: high

Issuer-owned persistent policy state for the two reviewed browser clients only. Support mandatory and optional-after-enrollment; explicit application AAL2 always wins. Reject ambiguous or unsupported weakening, stale confirmation, wrong role/audience and replay with altered intent. Durable receipts and guarded rollback survive issuer replacement. Portal carries verified identity, no admin credential. Changes affect subsequent authorization, not already issued tokens.

Verify onboarding and publish the scoped release

id: USER-WP-0033-T03
status: progress
priority: high

Test no-factor/password-only, pending/cancel/confirmed enrollment, enrolled OTP, old AAL1 sessions, mandatory/explicit AAL2, provider outage/recovery, privileged portal denial and policy preview/apply/replay/rollback. Use actual installed provider in isolated fixtures, browser tests and native non-mutating readback. Enable only vergabe-demo-company and user-engine-portal optional policies after privileged guards pass. Record canonical deployment and rollback evidence.

Resumed after interruption: portal browser 30/30, policy tests 5/5, issuer policy regressions and rollout tests pass. Installed-provider acceptance Job provider-p06-browser-46713f7e passed native optional/old-session OTP plus five browser checks. Fixed test endpoint and asynchronous TOTP/detail readiness. Release and live readback remain in progress. See P06 evidence.