docs(auth): record unified sign-in evidence
CI and Deploy / test (pull_request) Failing after 1m30s
CI and Deploy / deploy (pull_request) Has been skipped

This commit is contained in:
cesnimda
2026-08-09 17:06:08 +02:00
parent 93b869259e
commit 378807b3b9
11 changed files with 97 additions and 28 deletions
+12 -12
View File
@@ -2,17 +2,17 @@
Updated: 2026-08-09
- **Exact current task:** UX-001 — replace `LoginPage` local/Google/Microsoft tabs with one accessible sign-in card while preserving the hardened provider callbacks and separate registration behavior.
- **Last completed step:** AI-004 implementation `c3c5af8` was committed and pushed. Upload/reprocess/rebuild/improve now use one durable `cv.process` operation; duplicate active work is reused; provider failure state, persistent notifications, review gate and operation UI are covered. UX-001 source requirements were re-read and the current separate-tab/provider-card path was located.
- **Files currently modified:** tracking/evidence documents for AI-004 and the UX-001 status transition. No UX application code is modified yet.
- **Commands already run:** initial clean-tree review and push through `39e9804`; AI-004 source trace; local-cache-only restore; backend builds/focused/full tests; focused/full frontend tests/build; diff review; implementation commit/push; UX-001 source/route trace. See V-104V-107.
- **Test results:** backend 594/594; AI-004 focused backend 40/40; frontend 47/47 suites and 161/161 tests; profile UI 10/10; production frontend build and diff check pass. Synthetic CV/fake model only.
- **Services currently running:** none started by this session. Node/Jest/build processes exited. Pre-existing Docker services were not changed.
- **Temporary files or processes:** none created for AI-004. No dependency declaration, database or artifact was changed.
- **Exact current task:** UX-002 — revalidate every theme-state source and implement deterministic saved-user/anonymous/system precedence without startup flash or cross-tab loops.
- **Last completed step:** UX-001 implementation `93b8692` was committed. Login now uses one username-or-email/password card with sign-in-only Google/Microsoft presentations; focused/full frontend tests, build and local responsive dark-theme browser checks pass. Evidence/tracking are ready for their own commit and push.
- **Files currently modified:** UX-001 verification/evidence/tracking documents and three synthetic screenshots under `docs/audits/evidence/ux-001/`. UX-001 application code is committed.
- **Commands already run:** initial clean-tree review/push; AI-004 implementation/evidence commits/push; UX-001 complete source trace; focused 13/13 and full 166/166 frontend tests; production build; diff checks; local browser at 375/768/1440; implementation commit. See V-104V-110.
- **Test results:** backend baseline 594/594; frontend 47/47 suites and 166/166 tests; UX-001 focused 13/13; production frontend build and diff check pass. Browser local form passed in dark theme at 375/768/1440 with no measured overflow. Provider browser tests remain mocked.
- **Services currently running:** Next development server on `http://localhost:3000` in exec session `62719`; in-app browser tab open at `/login`. Pre-existing Docker services were not changed.
- **Temporary files or processes:** only the local Next development server and in-app browser tab. Stop the server before final handoff. No dependency declaration, database or private artifact changed.
- **Production changes currently active:** none. No deployment, provider/model call, private CV access, model pull, paid service, production migration or external payload occurred.
- **Rollback status:** AI-004 rollback is documented in `docs/verification/ai-004-cv-processing-queue.md`; worker switches remain default-off. Production is unchanged.
- **Uncommitted changes:** AI-004 evidence/master tracking status updates only; commit and push them before UX code.
- **Known failures:** browser localhost denied; MariaDB/SMTP/production unavailable; SEC-006 upgrades require explicit internet/package-index permission; complete parser cancellation/isolation remains SEC-007; historical clean EF-only SQLite chain needs startup reconciliation; Jest reports its existing force-exit/open-handle notice. Live CV 504/restart/private-file behavior is not claimed.
- **Exact next action:** read `LoginPage.tsx`, `GoogleAuthCard.tsx`, `MicrosoftAuthCard.tsx` and `login-page.test.tsx` completely; isolate sign-in-only button rendering from profile linking controls; replace tabs with one form/separator/two alternative buttons and add invalid/provider cancel/return/accessibility component tests.
- **Work that can continue independently:** UX-001 repository UI/tests; then UX-002/QA-001 source work. SEC-006/007 await package-index permission; PROD-001/003/004 await production access.
- **Rollback status:** UX-001 has no schema/config migration; revert `93b8692` to restore tabs. AI-004 rollback is documented in its verification record; worker switches remain default-off. Production is unchanged.
- **Uncommitted changes:** UX-001 evidence/master tracking documents and screenshots only; commit/push these before UX-002 application code.
- **Known failures:** light/System and configured/real-provider UX-001 browser checks remain; MariaDB/SMTP/production unavailable; SEC-006 upgrades require explicit internet/package-index permission; complete parser cancellation/isolation remains SEC-007; historical clean EF-only SQLite chain needs startup reconciliation; Jest reports its existing force-exit/open-handle notice.
- **Exact next action:** commit and push UX-001 evidence, then read `work.md:102-133`, `App.tsx`, `themePrefs.ts`, auth user-key transitions and theme tests completely; reproduce refresh/login/logout/cross-tab precedence before editing.
- **Work that can continue independently:** UX-002 and QA-001 repository work. SEC-006/007 await package-index permission; PROD-001/003/004 await production access.
- **Decisions still required from the user:** none for synthetic repository work. Internet/package upgrades, private CV access, external/paid providers and production actions retain their explicit approval/safety gates; SEC-009 retention/legal policy remains unresolved.