user-engine/docs/evidence/2026-09-13-account-clarity.md
tegwick 75750c0036
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record live account-clarity checks and remaining role journey acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 10:13:42 +02:00

53 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Account clarity rollout — 2026-09-13
Source: user-engine a9ff77d21db5316d49d8d54519a490ca21951bc7.
CI: user-engine image workflow run 133, success; CI smoke run 132, both jobs success.
Image: `forgejo.coulomb.social/coulomb/user-engine@sha256:558e489f0b6e0b7160ab0d370560a66497e12488b95531bbccca122b46331a6f`.
Runtime package pin: rapp-user-engine 367bb1b.
Applied an image-only JSON patch after checking cluster UID, deployment UID,
resource version, predecessor digest and absent MFA management URL. The deployment
rolled out successfully, Ready 1/1. Kept the existing Recreate strategy and resource
requests; process-local portal sessions are invalidated on restart. No provider
credential, OTP policy, enrollment setting, database or tenant membership changed.
Unrelated hostname edits in the runtime package were preserved unstaged.
## Validation
- `PYTHONDONTWRITEBYTECODE=1 make test` in user-engine: 188 tests, 3 optional skips;
layer conformance passed. Includes synthetic authenticated member/operator,
expired/anonymous session controls, browser denial, API JSON, OTP handoff URL
validation and untrusted recovery-parameter tests.
- `PYTHONDONTWRITEBYTECODE=1 make check` in rapp-user-engine: 4 packaging tests passed.
- `git diff --check` passed in both repositories.
- Eight live HTTP assertions passed: anonymous home, recovery, logged-out and
security controls/no-store; unavailable OTP setup without parameter spoofing;
HTML browser denial; unchanged JSON API denial; readiness.
- Twelve isolated Chromium assertions passed: public recovery, Sign in without
portal logout, reachable identity switching, unavailable OTP setup, OTP-help
return route, security page fitting a 390px viewport, HTML denial recovery,
expired issuer callback stripping query parameters, shared sign-out confirmation,
real browser POST through Authelia to portal, appropriate post-sign-out control,
and truthful portal-session wording.
No header overrides, reused personal browser profile, actual account credentials,
or OTP values were used. Anonymous browser checks do not prove authenticated
identity switching or provider enrollment. Script copies are in the session's
/tmp/account-clarity directory; durable acceptance cases are under tests/.
## Open acceptance
The provider factor-read credential remains rejected and its approved custody and
renewal contract is unpublished. `USER_ENGINE_MFA_MANAGEMENT_URL` remains unset.
The public help page does not claim OTP is off or enabled. Complete KEY-WP-0035
and USER-WP-0027-T04 before enabling the provider handoff or optional live policy.
The 29 role-based journeys and their remaining implementation/acceptance gaps
are in ../account-journeys.md. USER-WP-0027 stays active for T04T06; authoritative
workload discovery remains USER-WP-0026-T03. VERGABE-WP-0019 real-user acceptance
remains open.
Rollback: CAS image-only replacement with the predecessor
`sha256:8621032bacc3da5a4c8c96775422263d4b0cf775744126aa50c002b0a678ec5b`,
then reconcile both runtime manifest and Makefile pins. This reverts the UI and
restarts portal sessions; no database migration accompanied this release.