docs: record simplified password lifecycle

This commit is contained in:
inman
2026-09-02 11:23:02 +08:00
parent 029c8c6a59
commit ed456e6a5d
7 changed files with 62 additions and 4 deletions

View File

@@ -17,6 +17,7 @@ The platform already required login but treated the fixed deployment scope as a
- Keep one internal `organization_id` deployment scope and do not expose organization selection or tenant administration.
- Use three roles: `admin`, `team_lead`, and `user`.
- Administrators manage account lifecycle, passwords, sessions, global settings/audit, AgentBus/system tasks, and all manual tasks. They always hold all 18 registered manual business routes.
- Password entry points require a non-empty value but impose no application-level minimum or maximum length. The platform does not force a password change on first login or after an administrator reset; voluntary self-service change, administrator reset, and session revocation remain supported. The historical `must_change_password` column is compatibility-only and is cleared on password writes.
- Team leads and ordinary users use normal business APIs only for their own manual tasks. New non-administrator accounts start with no task-type grants and may invoke only routes explicitly granted by an administrator.
- Re-read route authorization before intake and relevant task state transitions. Known denied routes and unknown/non-unique routes fail closed before parsing, plugin dispatch, or ERP execution.
- Give team leads a dedicated read-only platform-operations dashboard over all manual account tasks. It is an aggregate-first leadership view across task, person, original input, final output, time, task type, and completion state; every aggregate may drill into the same bounded business-facing task projection.
@@ -32,6 +33,7 @@ This model fits a single-organization deployment while enforcing least privilege
- Migrations 015–017 must be applied before the updated control plane starts.
- Existing accounts migrate as administrators; newly created team leads and users require explicit task grants.
- Existing historical `must_change_password=true` values do not restrict login, reads, or mutations; no destructive migration is required to retire the forced-change flow.
- Permission revocation can block an existing task at confirmation or browser claim even when an administrator attempts the transition.
- Cross-user operational visibility is intentionally separated from normal task mutation and technical debugging surfaces.
- Dashboard acceptance is based on leadership questions and business-readable drill-through, not on reproducing task history or technical audit records.

View File

@@ -10,7 +10,7 @@
| RELEASE-001 | Current artifacts, filenames, versions, and SHA-256 values are defined only by `dist/release-manifest.json`. | Active | 2026-08-28 | Release and delivery | [Release manifest](../../dist/release-manifest.json) |
| SAFETY-001 | Real ERP access/write, task mutation, extension reload, service restart, deployment, and external delivery require explicit task-scoped authorization. | Active | 2026-08-28 | Operations and maintenance | [Governance](../../AGENTS.md) |
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, an aggregate-first read-only leadership dashboard, and explicit non-admin task-route allowlists. | Active | 2026-09-01 | Authentication, authorization, audit, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, an aggregate-first read-only leadership dashboard, explicit non-admin task-route allowlists, and no first-login forced-password-change workflow. | Active | 2026-09-01 | Authentication, authorization, audit, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
## Superseded Decisions

View File

@@ -22,6 +22,7 @@ Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/A
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
- Platform envelope fields such as task ID, account identity, authorization revision, session, parser decision, confirmation, transport, and audit never enter the business operation.
- The product is one fixed internal organization scope with three roles. Administrators manage accounts and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard.
- Account passwords are accepted when non-empty without an application-level length rule. First-login forced password changes are disabled; voluntary changes and administrator resets still revoke the relevant sessions, while the historical `must_change_password` column remains compatibility-only storage.
- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore; physical purge is not an operator capability.
@@ -44,4 +45,4 @@ Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/A
## Last Updated
2026-09-01
2026-09-02

View File

@@ -13,6 +13,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
- Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
- Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction.
- Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
## Current Focus
@@ -29,6 +30,7 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
- 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
- 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
## In Progress
@@ -56,4 +58,4 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
## Last Updated
2026-09-01
2026-09-02

View File

@@ -0,0 +1,51 @@
# Task: Promote simplified password lifecycle
## Identity
- Task ID: 20260902-promote-password-flow-c81d42
- Mode: Integration
- Branch: main
- Worktree: /Users/inmanx/Documents/lwltAPI
- Base commit: 029c8c6a59215cb6c3f8d7f126c4313730b2abb2
- Owner: codex
- Status: Ready for Integration
## Scope
- Promote the accepted password-lifecycle facts from feature task `20260902-registration-invalid-params-59f94692` and merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` into canonical project memory.
- Reconcile `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
- Run the task-aware project-document gate and complete repository verification from a base commit that already contains the source task record and evidence.
## Intent And Constraints
- Record the user's explicit product decision: passwords require a non-empty value but have no application-level length restriction, and first-login forced password changes are disabled.
- Preserve voluntary password change, administrator reset, session revocation, account roles, owner isolation, route grants, audit, dashboard behavior, and ERP safety boundaries.
- Treat the historical `must_change_password` column as compatibility-only; do not add a destructive migration.
- Do not restart or deploy services, mutate live accounts/database rows, access ERP, or send data externally.
## Outcome
- Accepted the source task's promotion candidates without semantic conflict because the user directly confirmed the product behavior.
- Updated `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
- Recorded merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` and this integration task under `Integrated Through`.
- No runtime, database, ERP, external-system, deployment, or service-process state was changed.
## Verification
- Source merge verification: repository check 10/10, control-plane 153/153, legacy 260/260, TypeScript check/build, JavaScript syntax, and diff checks passed on integrated `main`.
- `check_project_docs.py`: passed.
- `check_doc_drift.py --task-id 20260902-promote-password-flow-c81d42`: passed for all canonical writes.
- `git diff --check`: passed.
- `node --run check:repo`: 10/10 passed after canonical integration.
- `node --run check`: passed after canonical integration.
- `node --run test:control-plane`: 153/153 passed after canonical integration.
- `node --run test:legacy`: 260/260 passed after canonical integration.
- `node --run build`: passed after canonical integration.
## Follow-ups
- Restart or redeploy the standard service only under separate explicit authorization before relying on the new backend behavior in the running process.
## Promotion Candidates
- None. The accepted feature candidates were promoted in this integration task.

View File

@@ -5,6 +5,7 @@
- `agent设计规范/business-adaptation-registry.md` is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.
- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
- The platform exposes one fixed deployment scope, not an organization-management product. Accounts use `admin`, `team_lead`, and `user` roles.
- Passwords must be non-empty but have no application-level length restriction. First login and administrator password reset do not force a subsequent password change; users may still change passwords voluntarily, administrators may reset them, and password changes revoke existing sessions according to the account lifecycle contract.
- Administrators always hold all 18 manual business routes. Team leads and ordinary users start with no task grants, require explicit administrator allowlists, and may use normal task APIs only for their own manual tasks.
- A known ungranted route or a non-unique/unresolved route for a non-administrator fails before parsing, plugin dispatch, or ERP execution. Authorization is rechecked for supplemental input, attachments, confirmation, automatic confirmation, and browser claim.
- Team leads may read all manual account work only through the platform-operations dashboard. The dashboard is aggregate-first across task, person, original input, final output, time, task type, and completion state, with business-facing drill-through. It is not an audit log and never renders technical payloads, internal identifiers, machine-shaped historical input, or technical failure text; this visibility does not grant cross-user task mutation, artifacts, SSE, global settings, audit administration, or AgentBus access.
@@ -27,4 +28,4 @@
## Last Reviewed
2026-09-01
2026-09-02

View File

@@ -14,6 +14,7 @@ Use this index for searchable, traceable evidence records.
| 2026-08-31 | Production attachment failure | Root cause verified from supplied log | [Log-inspection task](../30-worklog/tasks/20260831-inspect-server-log-5d1e8a7c.md) | The original task remained waiting; the later structured attachment failed because DNS returned a private/reserved address. |
| 2026-09-01 | Fixed-scope account authorization and dashboard | Repository and standard local runtime verified | [Integration task](../30-worklog/tasks/20260901-integrate-account-system-7b2f4d.md) | Three roles, owner isolation, creator/input audit, archive/restore, leadership dashboard, and 18-route allowlists passed full regression; migrations 015–017 and standard-panel readiness were verified. |
| 2026-09-01 | Leadership platform-operations dashboard | Repository and authenticated browser verified | [Feature task](../30-worklog/tasks/20260901-leadership-dashboard-c4b9e1.md) | Aggregate-first task/person/input/output/time/type/completion presentation, business-safe projections, clickable drill-through, and full regression passed against the standard 8786 runtime. |
| 2026-09-02 | Account registration password rejection and simplified password lifecycle | Root cause and repository fix verified; runtime not restarted | [Evidence record](topics/20260902-registration-invalid-params-59f94692__account-registration-password-validation.md) | Privacy-safe diagnostics isolated the original rejection to `password`; the user then selected non-empty-only passwords and removal of first-login forced changes, with full regression coverage. |
## When To Add Evidence