Authentication migration remaining work¶
This delivery ledger reconciles the August 27 handover with September 5 code and read-only observations. The parity contract and M005 roadmap remain normative. Code delivery does not authorize credential setup, live-user migration or cutover.
Implementation ownership and acceptance¶
| Slice | Owner | Status | Completion evidence |
|---|---|---|---|
| Authentication evidence (#2921, PR #2928) | Root auth task | PR #2928 in review; 1,203 Identity and 1,244 API tests pass | Supported methods, malformed/missing evidence, refresh preservation, full request binding and majority consumed-nonce replay fence. Operation-bound freshness remains intact; current-head review, CI and merge still required. |
| Optional MFA after passkey sign-in (PR #2932, parent #2466) | Root auth task, after #2928 | Open stacked PR; 1,213 Identity tests pass after parent refresh | Configured MFA cannot be bypassed; passkey/MFA/recovery integration tests and combined evidence pass. Retarget to main and obtain current-head review/CI after dependency merge. |
| Emailed single-use step-up factor (parent #2466) | Root auth task, after #2932 | PR #3221 stacked; 1,247 Identity tests pass after parent refresh | Waiting/redemption UI, expiry/replay/wrong-account/wrong-operation rejection, configured MFA, safe continuation, recoverable delivery failure; current-head review and CI still required. |
| Link/unlink notification templates | Root auth task | PR #3215 in review | Port transactional wording, include helpdesk@syrf.org.uk, test encoded message content and preserve lifecycle mutation behavior. |
| Lockout disclosure (#2904) | Root auth task | PR #3237 in review; attacker-triggered lockout prevention included in the same slice | Uniform public response, bounded owner notification, shared anonymous-attempt budgets and a single-use mailbox permit for one password check; existing eligibility and MFA lockout remain enforced. Review/CI and merge remain pending. |
| Reset/resend timing (#2833) | Root auth task | PR #3233 in review; 1,180 Identity and 731 migration tests pass | API twins and Razor forgot-password covered; preserve reset access and non-enumerating responses, verify bounded queue, failure/delivery and restart behavior. PR #3237 is stacked on this slice. |
| API log redaction (#2834) | Root auth task | PR #3222 in review; 1,241 API tests pass, including 14 privacy cases | Structured Pii properties, no credentials or interpolated identifiers, poisoned-exception sentinel tests. |
| Deletion failure UI (#2911) | Root auth task | PR #3220 in review; 30 API and 109 Angular tests pass | Both active deactivation and unavailable deletion failures receive guidance; deletion stays unavailable by explicit user decision. A 30-second client timeout reports unknown without automatic retry or sign-out. Retry does not promise account survival. Existing deactivation/deletion semantic mismatch is separately tracked in #3227. |
| Pending-claim recovery UX (#2922) | Root auth task | Default-off PR #3229 in review; 1,175 Identity tests pass | Pending/resolved/rejected/repeated read-only retries and GET/form-POST authorization parity; no application admission before verified immutable mapping. Non-gating for synthetic rehearsal, gating before real users. |
| Campaign finalization (#2923) | Root auth task | PR #3214 in review; 769 full migration tests plus final 32 focused tests pass | CLI plus rendered chart operation; require valid zero-write declaration before importing, reject source/live Google subject/current role drift, retain temporarily locked recipients and operational S12 execution gate. Two role tests were added after the full-suite build and passed in the focused run. |
| Shipped dependencies (#2907) | Root auth task | #3217 merged; #3216 and #3219 in review | #3216 couples Mongo 3.10 with Elastic APM 1.33, with real compression/diagnostic dispatch and BSON/CSUUID tests; no unsafe standalone compression override. #3219 passes OTLP trace/metric and logging compatibility tests. Test-only SSH.NET findings remain open. |
| Documentation reconciliation | Root auth task | In progress | Each historical claim linked to current code/merge evidence; missing operational evidence never marked complete from pod health alone. |
Every implementation PR uses ship-pr: substantive review of the current head, actionable findings resolved, required CI rechecked after changes, and the configured admin-triggered /approve workflow for the approving GitHub review. No additional human approval is inferred. Record the reviewed SHA, check results, merge SHA, post-merge validation and cleanup outcome. Cleanup preserves unrelated concurrent worktrees; narrow passing tests alone do not close integrated feature acceptance.
Already implemented¶
PRs #2901, #2902, #2905 and #2906 merged August 27. PR #2925 requires SyRF-owned mailbox confirmation; #2926 shares SyRF userinfo claim projection; #2930 handles external-link failures without an unhandled 500. Current external-registration compensation reconciles account absence before releasing reservations, with cancellation tests. Session revocation returns failure on cancellation and distinguishes cancellation before either store call. Reconcile the completed portions of #2835, #2836 and #2919 rather than reimplementing them.
The current Investigator resolver rejects unmapped GUID subjects. Preserve mapping tombstones, provider-key ownership, non-enumerating registration, confirmation/profile admission and revocation-before-deletion semantics.
Operational evidence and later gates¶
Non-blocking progressive enhancements remain explicitly owned and ordered after their delivering slices: #3259 tracks reusable privacy scopes and bounded diagnostics; #3260 tracks optional authentication test hardening (including consistent injected-clock support for advanced-time BFF evidence tests); #3261 tracks bounded campaign-checkpoint diagnostics after #3214. These do not waive correctness, security, regression or required CI findings in the current PRs. Freshness-cookie replay prevention is an intrinsic #2928 blocker and is implemented in that slice, not deferred.
The canonical issue/PR mapping and slice acceptance are recorded on #2466. All twelve remaining implementation PRs are open at this September 5 checkpoint;
3217 is merged. Neither parent #2466 nor epic #2418 closes on these partial¶
repository deliveries. The #2907 dependency umbrella retains test-only SSH.NET work. This ledger does not assign a sprint or claim any live gate has completed.
On September 5, read-only Kubernetes inspection found staging Identity 1.37.0 available at 2/2 replicas; its public OIDC discovery responded and staging Web configuration selected Auth0. This does not establish S08 acceptance completion. The inspected cluster-gitops revision contains no SyRF Redis/Valkey or OTLP configuration. Mailbox availability is unknown, not disproved by absent Git files.
- Reconcile S08 render, secret-contract, mount/use, forwarding, ring and artifact audit evidence; implement S08A session infrastructure; execute S30's full synthetic ingress/application matrix and separate teardown.
- S09 completes the staging Auth0 rollback before S27 separately reapplies OpenIddict. Each direction has distinct revisions, syncs and fresh generations.
- S10 production dark launch precedes S11's exact 24-hour BFF/Auth0 baseline and S12 campaign. S13 requires reconciliation, backup-restore evidence and readiness: privileged 100%, active-90-day 95%, all-enabled 90%, Google-only 90%.
- S14 requires four reviews spanning at least 28 days, zero Auth0 traffic, no Sev-½ and no unexplained mismatch before runtime cleanup.
- Preserve M005's cleanup dependency graph, including the buildable S17/S24/S25 unit, S19 rollback, S28 reapply, S20 promotion, S21 secrets and S22 authorized external retirement. Tie #2915's two anonymous lookup endpoints to removal of their Auth0/SPA consumers; earlier closure requires coordinated Auth0 work.
Retain redacted per-operation campaign evidence before the next GitOps sync can prune the previous Job. No current observation proves the live matrix has passed.