user-engine/workplans/USER-WP-0026-account-recovery.md
tegwick e54b6ee970
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 1m21s
Add account recovery, visible access records and shared sign-out handoff
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:34:44 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated
USER-WP-0026 workplan Account recovery and visible identity and access communication user-engine active codex user-engine 2026-09-12 2026-09-12

The operator reports a dead-end authentication error after using an account outside the product tenant. Recent issuer telemetry indicates token exchange failure; tenant rejection and provider failure must not be conflated.

Implement and validate recovery

id: USER-WP-0026-T01
status: done
priority: high

Route failed browser login to the public account recovery surface without codes, state or unverified identity. Show verified portal identity, tenant memberships, and recorded workload memberships; preserve operator/customer separation. Provide CSRF-protected portal logout and confirmed shared provider sign-out with fixed owner-configured return locations. No automatic reauthentication loops, MFA downgrade, global JWT revocation claim or inferred workload entitlements.

Publish and verify the recovery flow

id: USER-WP-0026-T02
status: progress
priority: high

Publish immutable images, update canonical runtime pins, verify anonymous recovery and sign-out confirmation live, and record actual account switching only after browser evidence. Existing application sessions may outlive provider logout. Related: USER-WP-0025-T03 and VERGABE-WP-0019-T06.

Source verification: 182 tests passed with three optional integration skips; layer conformance passed. Immutable publication and live checks are in progress.