Route rejected company sign-in to central account recovery
All checks were successful
Application acceptance / application-tests (push) Successful in 1m8s
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 30s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-12 10:34:44 +02:00
parent c1727ed14d
commit c067993037
5 changed files with 54 additions and 13 deletions

View file

@ -73,3 +73,12 @@ fresh sign-in and any provider-required MFA, confirm their account, and enter
the company workflow. Do not substitute an operator session. Recovery and
two-user workflow acceptance remain the existing RAPPS-WP-0014-T03 and
VERGABE-WP-0019-T04 tasks.
## Rejected-login recovery
Rejected callbacks and unusable confirmations clear pending identity state and
redirect to `NETKINGDOM_ACCOUNT_PORTAL_URL` + `/access-recovery` (default canonical
users.coulomb.social). The response is no-store and no-referrer; callback codes,
state and unverified identity are never forwarded. The central portal offers
verified account details and confirmed shared sign-out. Admission, CSRF, tenant,
principal and MFA rules remain enforced before any product account is created.