docs(auth): record unified sign-in evidence
This commit is contained in:
@@ -309,3 +309,13 @@
|
||||
- **Consequences:** all four long CV actions share one default-off worker and operation UI. Parser-version/process isolation remains SEC-006/007; browser/model/MariaDB/production gates remain before rollout. Existing clients must accept the upload endpoint's 202 operation response.
|
||||
- **User approval required:** No; both programmes explicitly require one durable operation foundation and preservation of human review.
|
||||
- **Reversible:** Yes. Keep the worker off, revert `c3c5af8`, and retain operation/extraction rows. Cancel or drain `cv.process` rows before removing the handler.
|
||||
|
||||
## DEC-032 — Provider account management and signed-out authentication share logic, not presentation
|
||||
|
||||
- **Date:** 2026-08-09
|
||||
- **Decision:** Add an explicit sign-in presentation to the existing Google and Microsoft components. It reuses provider token exchange and two-factor handling but skips signed-in account discovery, link/unlink controls and linking copy. Keep the full account presentation unchanged for authenticated profile/settings surfaces.
|
||||
- **Reason/evidence:** the programme requires a conventional single sign-in card without implying account linking. Duplicating provider callback code would risk divergence from the hardened tenant/linking path, while rendering account-state panels on login creates the prohibited clutter and misleading relationship.
|
||||
- **Alternatives considered:** retain tabs; create duplicate login-only provider clients; hide copy with CSS; combine provider exchange and account linking. These preserve the UX defect, duplicate sensitive logic, hide rather than remove inaccessible state, or weaken the identity boundary.
|
||||
- **Consequences:** login presentation becomes simpler without changing backend identity ownership. Provider account management remains available only in its existing authenticated surfaces. Real-provider and production verification are still required.
|
||||
- **User approval required:** No; this is the smallest implementation of the explicit UX-001 requirement and preserves the prior security contracts.
|
||||
- **Reversible:** Yes. Reverting UX-001 restores the tabbed presentation; no provider link, session, schema or configuration data changes.
|
||||
|
||||
@@ -2,17 +2,17 @@
|
||||
|
||||
Updated: 2026-08-09
|
||||
|
||||
- **Overall programme status:** Active. Six packages are locally verified; fourteen packages through AI-004 are implemented with automated/runtime evidence but blocked from applicable parser/browser/model/provider/production gates; UX-001 is in progress.
|
||||
- **Current work package:** `UX-001` — unified authentication page (`IN PROGRESS`); source requirement re-read and existing tab/provider-card structure traced.
|
||||
- **Overall programme status:** Active. Six packages are locally verified; fifteen packages through UX-001 are implemented with automated/runtime evidence but blocked from applicable theme/provider/production gates; UX-002 is in progress.
|
||||
- **Current work package:** `UX-002` — deterministic theme state (`IN PROGRESS`); UX-001 browser evidence showed that explicit anonymous preference/refresh behavior must be verified here.
|
||||
- **Completed work packages:** None are `DONE`; all repository security/AI packages still have applicable browser, provider and/or production gates.
|
||||
- **Locally verified work:** SEC-001, SEC-002, SEC-003, SEC-005A, CORE-001 and PROD-002 (`VERIFIED LOCALLY`).
|
||||
- **Implemented, verification incomplete:** SEC-004, SEC-005B, SEC-008, CORE-002, BG-001, OPS-001A/B/C, POL-001/002, AI-001/002/003/004 (`IMPLEMENTED — NOT VERIFIED`). AI-004 now returns 202 for upload and uses the shared typed worker/status/notification/UI contract; the worker remains default-off and parser hardening remains blocked.
|
||||
- **Implemented, verification incomplete:** SEC-004, SEC-005B, SEC-008, CORE-002, BG-001, OPS-001A/B/C, POL-001/002, AI-001/002/003/004 and UX-001 (`IMPLEMENTED — NOT VERIFIED`). UX-001 now presents one local/provider sign-in card and passes component, full frontend, build and responsive dark-theme browser checks; light/System/configured-provider/production gates remain.
|
||||
- **Production-verified work:** None.
|
||||
- **Blocked work:** SEC-006 requires explicit internet/package-index permission; PROD-001/003/004 and REL-001 require documented production access and unfinished dependencies. Browser access is denied by browser administrator policy; SMTP/MariaDB environments are unavailable.
|
||||
- **Blocked work:** SEC-006 requires explicit internet/package-index permission; PROD-001/003/004 and REL-001 require documented production access and unfinished dependencies. Real provider, SMTP/MariaDB and production environments are unavailable; the in-app browser is available for local UI checks.
|
||||
- **Deferred work:** None. Conditional multi-replica coordination, model deletion, realtime operation delivery and unrelated production changes remain outside current packages.
|
||||
- **Next five work packages:** UX-001 unified authentication; QA-001 job-analysis/keyword quality; UX-002 deterministic theme state; CAREER-001 Career Workspace redesign; CAREER-002 CV Builder redesign. SEC-006/007 resume after package-index permission.
|
||||
- **Status counts:** 6 `VERIFIED LOCALLY`; 14 `IMPLEMENTED — NOT VERIFIED`; 1 `IN PROGRESS`; 13 `NOT STARTED`; 5 `BLOCKED`; 0 `DONE`; 0 `DEFERRED`.
|
||||
- **Test status:** backend 594/594; AI-004 focused backend 40/40; frontend 47/47 suites and 161/161 tests, AI-004 focused UI 10/10, production build pass; prior sidecar 22/22. Patch check passes. Browser/model/MariaDB/production checks were not run.
|
||||
- **Next five work packages:** UX-002 deterministic theme state; QA-001 job-analysis/keyword quality; CAREER-001 Career Workspace redesign; CAREER-002 CV Builder redesign; EMAIL-001 consolidated email experience. SEC-006/007 resume after package-index permission.
|
||||
- **Status counts:** 6 `VERIFIED LOCALLY`; 15 `IMPLEMENTED — NOT VERIFIED`; 1 `IN PROGRESS`; 12 `NOT STARTED`; 5 `BLOCKED`; 0 `DONE`; 0 `DEFERRED`.
|
||||
- **Test status:** backend 594/594; AI-004 focused backend 40/40; frontend 47/47 suites and 166/166 tests, UX-001 focused 13/13, production build pass; prior sidecar 22/22. Patch check passes. UX-001 dark-theme browser smoke passed at 375/768/1440; configured-provider/light-theme/model/MariaDB/production checks were not run.
|
||||
- **Deployment status:** No deployment performed. No production migrations were run. AI operation worker remains disabled by default.
|
||||
- **Production status:** Unchanged and unverified. No provider/model call, model pull, external request or paid API occurred.
|
||||
- **Known regressions:** None found by automated suites. Jest still needs `--forceExit` and reports its existing open-handle notice. Direct clean EF-only SQLite migration still hits the pre-existing historical blank-chain defect before later migrations; normal startup owns reconciliation. Cross-feature monthly AI usage accounting remains a rollout gap.
|
||||
@@ -41,5 +41,6 @@ Updated: 2026-08-09
|
||||
- `docs/verification/ai-002-provider-routing.md`
|
||||
- `docs/verification/ai-003-strategy-snapshot-queue.md`
|
||||
- `docs/verification/ai-004-cv-processing-queue.md`
|
||||
- `docs/verification/ux-001-unified-authentication.md`
|
||||
- `docs/verification/prod-002-ai-evaluation.md`
|
||||
- `docs/work-programmes/master-work-plan.md`
|
||||
|
||||
@@ -16,7 +16,7 @@ Allowed statuses are `NOT STARTED`, `IN PROGRESS`, `IMPLEMENTED — NOT VERIFIED
|
||||
|
||||
`DONE` requires every applicable acceptance criterion, focused and regression tests, browser/accessibility/theme/mobile checks, tenant and entitlement checks, documentation, migration/rollback evidence, and production verification. Repository-only work that still requires production is at most `VERIFIED LOCALLY`.
|
||||
|
||||
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **UX-001**.
|
||||
Exactly one implementation item may be `IN PROGRESS`. As of this revision it is **UX-002**.
|
||||
|
||||
## Consolidated dependency order
|
||||
|
||||
@@ -559,11 +559,11 @@ Ordering differences from the suggested list:
|
||||
- **Required tests:** invalid credentials/provider failure/cancel/return, focus/order/labels.
|
||||
- **Required browser verification:** 375/768/1440, light/dark, keyboard/focus, logged-out/provider mocks.
|
||||
- **Required production verification:** real provider smoke only with authorized accounts.
|
||||
- **Status:** `IN PROGRESS`.
|
||||
- **Blocker:** browser localhost policy and real-provider/production checks; component/source work can continue safely.
|
||||
- **Evidence:** source requirement re-read; initial trace confirms `LoginPage` still renders separate local/Google/Microsoft tabs and provider-card components.
|
||||
- **Commit:** none.
|
||||
- **Remaining work:** keep visual change separate from identity migration.
|
||||
- **Status:** `IMPLEMENTED — NOT VERIFIED`.
|
||||
- **Blocker:** light/System-theme browser, configured/real-provider and production checks require the UX-002 preference work plus authorized provider/deployment environments.
|
||||
- **Evidence:** `docs/verification/ux-001-unified-authentication.md`; V-108–V-110; focused 13/13, full frontend 47/47 suites and 166/166 tests, production build, responsive dark-theme browser captures at 375/768/1440.
|
||||
- **Commit:** `93b8692` (`feat(auth): unify sign-in options`).
|
||||
- **Remaining work:** light/System theme browser; configured-provider browser; real authorized Google/Microsoft cancel/return; production smoke. Keep identity migration separate.
|
||||
|
||||
### UX-002 — Deterministic theme state
|
||||
|
||||
@@ -577,9 +577,9 @@ Ordering differences from the suggested list:
|
||||
- **Required tests:** Light/Dark/System, login/logout/refresh/navigation/storage/preference listeners/tabs.
|
||||
- **Required browser verification:** 375/768/1440, light/dark/system, refresh/navigation/two tabs/reduced motion.
|
||||
- **Required production verification:** normal browser smoke after deploy.
|
||||
- **Status:** `NOT STARTED`.
|
||||
- **Status:** `IN PROGRESS`.
|
||||
- **Blocker:** none.
|
||||
- **Evidence:** reported behavior not yet reproduced.
|
||||
- **Evidence:** source requirement re-read is next; UX-001 browser storage limitation makes deterministic anonymous preference/refresh behavior the immediate dependency.
|
||||
- **Commit:** none.
|
||||
- **Remaining work:** trace root precedence before changing UI.
|
||||
|
||||
|
||||
@@ -2,17 +2,17 @@
|
||||
|
||||
Updated: 2026-08-09
|
||||
|
||||
- **Exact current task:** UX-001 — replace `LoginPage` local/Google/Microsoft tabs with one accessible sign-in card while preserving the hardened provider callbacks and separate registration behavior.
|
||||
- **Last completed step:** AI-004 implementation `c3c5af8` was committed and pushed. Upload/reprocess/rebuild/improve now use one durable `cv.process` operation; duplicate active work is reused; provider failure state, persistent notifications, review gate and operation UI are covered. UX-001 source requirements were re-read and the current separate-tab/provider-card path was located.
|
||||
- **Files currently modified:** tracking/evidence documents for AI-004 and the UX-001 status transition. No UX application code is modified yet.
|
||||
- **Commands already run:** initial clean-tree review and push through `39e9804`; AI-004 source trace; local-cache-only restore; backend builds/focused/full tests; focused/full frontend tests/build; diff review; implementation commit/push; UX-001 source/route trace. See V-104–V-107.
|
||||
- **Test results:** backend 594/594; AI-004 focused backend 40/40; frontend 47/47 suites and 161/161 tests; profile UI 10/10; production frontend build and diff check pass. Synthetic CV/fake model only.
|
||||
- **Services currently running:** none started by this session. Node/Jest/build processes exited. Pre-existing Docker services were not changed.
|
||||
- **Temporary files or processes:** none created for AI-004. No dependency declaration, database or artifact was changed.
|
||||
- **Exact current task:** UX-002 — revalidate every theme-state source and implement deterministic saved-user/anonymous/system precedence without startup flash or cross-tab loops.
|
||||
- **Last completed step:** UX-001 implementation `93b8692` was committed. Login now uses one username-or-email/password card with sign-in-only Google/Microsoft presentations; focused/full frontend tests, build and local responsive dark-theme browser checks pass. Evidence/tracking are ready for their own commit and push.
|
||||
- **Files currently modified:** UX-001 verification/evidence/tracking documents and three synthetic screenshots under `docs/audits/evidence/ux-001/`. UX-001 application code is committed.
|
||||
- **Commands already run:** initial clean-tree review/push; AI-004 implementation/evidence commits/push; UX-001 complete source trace; focused 13/13 and full 166/166 frontend tests; production build; diff checks; local browser at 375/768/1440; implementation commit. See V-104–V-110.
|
||||
- **Test results:** backend baseline 594/594; frontend 47/47 suites and 166/166 tests; UX-001 focused 13/13; production frontend build and diff check pass. Browser local form passed in dark theme at 375/768/1440 with no measured overflow. Provider browser tests remain mocked.
|
||||
- **Services currently running:** Next development server on `http://localhost:3000` in exec session `62719`; in-app browser tab open at `/login`. Pre-existing Docker services were not changed.
|
||||
- **Temporary files or processes:** only the local Next development server and in-app browser tab. Stop the server before final handoff. No dependency declaration, database or private artifact changed.
|
||||
- **Production changes currently active:** none. No deployment, provider/model call, private CV access, model pull, paid service, production migration or external payload occurred.
|
||||
- **Rollback status:** AI-004 rollback is documented in `docs/verification/ai-004-cv-processing-queue.md`; worker switches remain default-off. Production is unchanged.
|
||||
- **Uncommitted changes:** AI-004 evidence/master tracking status updates only; commit and push them before UX code.
|
||||
- **Known failures:** browser localhost denied; MariaDB/SMTP/production unavailable; SEC-006 upgrades require explicit internet/package-index permission; complete parser cancellation/isolation remains SEC-007; historical clean EF-only SQLite chain needs startup reconciliation; Jest reports its existing force-exit/open-handle notice. Live CV 504/restart/private-file behavior is not claimed.
|
||||
- **Exact next action:** read `LoginPage.tsx`, `GoogleAuthCard.tsx`, `MicrosoftAuthCard.tsx` and `login-page.test.tsx` completely; isolate sign-in-only button rendering from profile linking controls; replace tabs with one form/separator/two alternative buttons and add invalid/provider cancel/return/accessibility component tests.
|
||||
- **Work that can continue independently:** UX-001 repository UI/tests; then UX-002/QA-001 source work. SEC-006/007 await package-index permission; PROD-001/003/004 await production access.
|
||||
- **Rollback status:** UX-001 has no schema/config migration; revert `93b8692` to restore tabs. AI-004 rollback is documented in its verification record; worker switches remain default-off. Production is unchanged.
|
||||
- **Uncommitted changes:** UX-001 evidence/master tracking documents and screenshots only; commit/push these before UX-002 application code.
|
||||
- **Known failures:** light/System and configured/real-provider UX-001 browser checks remain; MariaDB/SMTP/production unavailable; SEC-006 upgrades require explicit internet/package-index permission; complete parser cancellation/isolation remains SEC-007; historical clean EF-only SQLite chain needs startup reconciliation; Jest reports its existing force-exit/open-handle notice.
|
||||
- **Exact next action:** commit and push UX-001 evidence, then read `work.md:102-133`, `App.tsx`, `themePrefs.ts`, auth user-key transitions and theme tests completely; reproduce refresh/login/logout/cross-tab precedence before editing.
|
||||
- **Work that can continue independently:** UX-002 and QA-001 repository work. SEC-006/007 await package-index permission; PROD-001/003/004 await production access.
|
||||
- **Decisions still required from the user:** none for synthetic repository work. Internet/package upgrades, private CV access, external/paid providers and production actions retain their explicit approval/safety gates; SEC-009 retention/legal policy remains unresolved.
|
||||
|
||||
Reference in New Issue
Block a user