|
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m55s
CI / Build container images (pull_request) Successful in 4m43s
CI / Auth e2e pack (pull_request) Successful in 9m13s
CI / Import/export fidelity gate (pull_request) Successful in 1m4s
CD / Deploy to Test (push) Blocked by required conditions
CD / Smoke tests against Test (push) Blocked by required conditions
CD / Promote to Int (push) Blocked by required conditions
CI / Auth e2e pack (push) Blocked by required conditions
CI / Import/export fidelity gate (push) Blocked by required conditions
CI / Build container images (push) Blocked by required conditions
CI / Lint, typecheck, test (push) Has been cancelled
CD / Build and push images (push) Has been cancelled
The deploy-level realization of auth.local.enabled (ADR 0021): FALSE answers 404 on every local credential flow — login, signup, e-mail verification, resend, password forgot/reset/change — enforced centrally in the auth guard via the @LocalCredentialFlow() marker before any session or CSRF logic runs. Deploy-level on purpose: a compromised Site Admin cannot reopen the local path, so the runtime-flip residual risk from ADR 0021 does not materialize (R-02 closed in the risk list). An enumeration fence fails when an auth route is neither marked nor on the reviewed allowlist, so a new credential flow cannot ship unswitched. Stated decisions, each tested: sessions/logout keep working for externally authenticated users; PAT and feed-token issuance stays available (API authorization under its own switches, not interactive sign-in). Bootstrap: complete setup (or SETUP_ADMIN_* pre-seed) before flipping; the api warns at boot when local auth is off with neither OIDC nor proxy auth configured. GET /auth/methods reports local:false and the login page hides the local form and credential links. Hardening guide: the planned auth.local.enabled row moves from 1.3 into the live deploy table with the bootstrap ordering, and the verification checklist gains the login-404 probe. Refs #216. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AUtYMxwTCMHG9mVHnwbFg8 |
||
|---|---|---|
| .. | ||
| editor-schema | ||
| permissions | ||
| admin-users.ts | ||
| api-error.ts | ||
| api-tokens.ts | ||
| auth.test.ts | ||
| auth.ts | ||
| backup-set.ts | ||
| backup-status.ts | ||
| backup-target-policy.test.ts | ||
| backup-target-policy.ts | ||
| collab-token.test.ts | ||
| collab-token.ts | ||
| comments.ts | ||
| conversion.ts | ||
| env.test.ts | ||
| env.ts | ||
| favorites.ts | ||
| feed-tokens.ts | ||
| files.ts | ||
| fonts.test.ts | ||
| fonts.ts | ||
| health.test.ts | ||
| health.ts | ||
| home.ts | ||
| i18n-tools.test.ts | ||
| i18n-tools.ts | ||
| index.ts | ||
| labels.test.ts | ||
| labels.ts | ||
| legal.ts | ||
| links.ts | ||
| members.ts | ||
| notifications.ts | ||
| pages.ts | ||
| plugins.ts | ||
| ponds.ts | ||
| public-api.ts | ||
| quotas.ts | ||
| search.test.ts | ||
| search.ts | ||
| secret-store.ts | ||
| setup.ts | ||
| system.ts | ||
| text-diff.test.ts | ||
| text-diff.ts | ||
| theme.test.ts | ||
| theme.ts | ||
| token-crypto.crossruntime.test.ts | ||
| token-crypto.ts | ||
| tree.ts | ||
| users.ts | ||
| watches.ts | ||
| webdav.test.ts | ||
| webdav.ts | ||