Skip to content

Authentication migration remaining work

This delivery ledger reconciles the August 27 handover with September 5 code and read-only observations. The parity contract and M005 roadmap remain normative. Code delivery does not authorize credential setup, live-user migration or cutover.

Implementation ownership and acceptance

Slice Owner Status Completion evidence
Authentication evidence (#2921, PR #2928) Root auth task PR #2928 in review; 1,203 Identity and 1,244 API tests pass Supported methods, malformed/missing evidence, refresh preservation, full request binding and majority consumed-nonce replay fence. Operation-bound freshness remains intact; current-head review, CI and merge still required.
Optional MFA after passkey sign-in (PR #2932, parent #2466) Root auth task, after #2928 Open stacked PR; 1,213 Identity tests pass after parent refresh Configured MFA cannot be bypassed; passkey/MFA/recovery integration tests and combined evidence pass. Retarget to main and obtain current-head review/CI after dependency merge.
Emailed single-use step-up factor (parent #2466) Root auth task, after #2932 PR #3221 stacked; 1,247 Identity tests pass after parent refresh Waiting/redemption UI, expiry/replay/wrong-account/wrong-operation rejection, configured MFA, safe continuation, recoverable delivery failure; current-head review and CI still required.
Link/unlink notification templates Root auth task PR #3215 in review Port transactional wording, include helpdesk@syrf.org.uk, test encoded message content and preserve lifecycle mutation behavior.
Lockout disclosure (#2904) Root auth task PR #3237 in review; attacker-triggered lockout prevention included in the same slice Uniform public response, bounded owner notification, shared anonymous-attempt budgets and a single-use mailbox permit for one password check; existing eligibility and MFA lockout remain enforced. Review/CI and merge remain pending.
Reset/resend timing (#2833) Root auth task PR #3233 in review; 1,180 Identity and 731 migration tests pass API twins and Razor forgot-password covered; preserve reset access and non-enumerating responses, verify bounded queue, failure/delivery and restart behavior. PR #3237 is stacked on this slice.
API log redaction (#2834) Root auth task PR #3222 in review; 1,241 API tests pass, including 14 privacy cases Structured Pii properties, no credentials or interpolated identifiers, poisoned-exception sentinel tests.
Deletion failure UI (#2911) Root auth task PR #3220 in review; 30 API and 109 Angular tests pass Both active deactivation and unavailable deletion failures receive guidance; deletion stays unavailable by explicit user decision. A 30-second client timeout reports unknown without automatic retry or sign-out. Retry does not promise account survival. Existing deactivation/deletion semantic mismatch is separately tracked in #3227.
Pending-claim recovery UX (#2922) Root auth task Default-off PR #3229 in review; 1,175 Identity tests pass Pending/resolved/rejected/repeated read-only retries and GET/form-POST authorization parity; no application admission before verified immutable mapping. Non-gating for synthetic rehearsal, gating before real users.
Campaign finalization (#2923) Root auth task PR #3214 in review; 769 full migration tests plus final 32 focused tests pass CLI plus rendered chart operation; require valid zero-write declaration before importing, reject source/live Google subject/current role drift, retain temporarily locked recipients and operational S12 execution gate. Two role tests were added after the full-suite build and passed in the focused run.
Shipped dependencies (#2907) Root auth task #3217 merged; #3216 and #3219 in review #3216 couples Mongo 3.10 with Elastic APM 1.33, with real compression/diagnostic dispatch and BSON/CSUUID tests; no unsafe standalone compression override. #3219 passes OTLP trace/metric and logging compatibility tests. Test-only SSH.NET findings remain open.
Documentation reconciliation Root auth task In progress Each historical claim linked to current code/merge evidence; missing operational evidence never marked complete from pod health alone.

Every implementation PR uses ship-pr: substantive review of the current head, actionable findings resolved, required CI rechecked after changes, and the configured admin-triggered /approve workflow for the approving GitHub review. No additional human approval is inferred. Record the reviewed SHA, check results, merge SHA, post-merge validation and cleanup outcome. Cleanup preserves unrelated concurrent worktrees; narrow passing tests alone do not close integrated feature acceptance.

Already implemented

PRs #2901, #2902, #2905 and #2906 merged August 27. PR #2925 requires SyRF-owned mailbox confirmation; #2926 shares SyRF userinfo claim projection; #2930 handles external-link failures without an unhandled 500. Current external-registration compensation reconciles account absence before releasing reservations, with cancellation tests. Session revocation returns failure on cancellation and distinguishes cancellation before either store call. Reconcile the completed portions of #2835, #2836 and #2919 rather than reimplementing them.

The current Investigator resolver rejects unmapped GUID subjects. Preserve mapping tombstones, provider-key ownership, non-enumerating registration, confirmation/profile admission and revocation-before-deletion semantics.

Operational evidence and later gates

Non-blocking progressive enhancements remain explicitly owned and ordered after their delivering slices: #3259 tracks reusable privacy scopes and bounded diagnostics; #3260 tracks optional authentication test hardening (including consistent injected-clock support for advanced-time BFF evidence tests); #3261 tracks bounded campaign-checkpoint diagnostics after #3214. These do not waive correctness, security, regression or required CI findings in the current PRs. Freshness-cookie replay prevention is an intrinsic #2928 blocker and is implemented in that slice, not deferred.

The canonical issue/PR mapping and slice acceptance are recorded on #2466. All twelve remaining implementation PRs are open at this September 5 checkpoint;

3217 is merged. Neither parent #2466 nor epic #2418 closes on these partial

repository deliveries. The #2907 dependency umbrella retains test-only SSH.NET work. This ledger does not assign a sprint or claim any live gate has completed.

On September 5, read-only Kubernetes inspection found staging Identity 1.37.0 available at 2/2 replicas; its public OIDC discovery responded and staging Web configuration selected Auth0. This does not establish S08 acceptance completion. The inspected cluster-gitops revision contains no SyRF Redis/Valkey or OTLP configuration. Mailbox availability is unknown, not disproved by absent Git files.

  1. Reconcile S08 render, secret-contract, mount/use, forwarding, ring and artifact audit evidence; implement S08A session infrastructure; execute S30's full synthetic ingress/application matrix and separate teardown.
  2. S09 completes the staging Auth0 rollback before S27 separately reapplies OpenIddict. Each direction has distinct revisions, syncs and fresh generations.
  3. S10 production dark launch precedes S11's exact 24-hour BFF/Auth0 baseline and S12 campaign. S13 requires reconciliation, backup-restore evidence and readiness: privileged 100%, active-90-day 95%, all-enabled 90%, Google-only 90%.
  4. S14 requires four reviews spanning at least 28 days, zero Auth0 traffic, no Sev-½ and no unexplained mismatch before runtime cleanup.
  5. Preserve M005's cleanup dependency graph, including the buildable S17/S24/S25 unit, S19 rollback, S28 reapply, S20 promotion, S21 secrets and S22 authorized external retirement. Tie #2915's two anonymous lookup endpoints to removal of their Auth0/SPA consumers; earlier closure requires coordinated Auth0 work.

Retain redacted per-operation campaign evidence before the next GitOps sync can prune the previous Job. No current observation proves the live matrix has passed.