docs: record simplified password lifecycle
This commit is contained in:
1 parent
029c8c6a59
commit
ed456e6a5d
7 files changed
+62
-4
No files matched your search
@@ -13,6 +13,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
|
||||
- Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
|
||||
- Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction.
|
||||
- Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
|
||||
|
||||
## Current Focus
|
||||
|
||||
@@ -29,6 +30,7 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
|
||||
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
|
||||
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
|
||||
- 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
|
||||
- 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
|
||||
|
||||
## In Progress
|
||||
|
||||
@@ -56,4 +58,4 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-09-01
|
||||
2026-09-02
|
||||
@@ -0,0 +1,51 @@
|
||||
# Task: Promote simplified password lifecycle
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260902-promote-password-flow-c81d42
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI
|
||||
- Base commit: 029c8c6a59215cb6c3f8d7f126c4313730b2abb2
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Promote the accepted password-lifecycle facts from feature task `20260902-registration-invalid-params-59f94692` and merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` into canonical project memory.
|
||||
- Reconcile `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
|
||||
- Run the task-aware project-document gate and complete repository verification from a base commit that already contains the source task record and evidence.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Record the user's explicit product decision: passwords require a non-empty value but have no application-level length restriction, and first-login forced password changes are disabled.
|
||||
- Preserve voluntary password change, administrator reset, session revocation, account roles, owner isolation, route grants, audit, dashboard behavior, and ERP safety boundaries.
|
||||
- Treat the historical `must_change_password` column as compatibility-only; do not add a destructive migration.
|
||||
- Do not restart or deploy services, mutate live accounts/database rows, access ERP, or send data externally.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Accepted the source task's promotion candidates without semantic conflict because the user directly confirmed the product behavior.
|
||||
- Updated `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
|
||||
- Recorded merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` and this integration task under `Integrated Through`.
|
||||
- No runtime, database, ERP, external-system, deployment, or service-process state was changed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Source merge verification: repository check 10/10, control-plane 153/153, legacy 260/260, TypeScript check/build, JavaScript syntax, and diff checks passed on integrated `main`.
|
||||
- `check_project_docs.py`: passed.
|
||||
- `check_doc_drift.py --task-id 20260902-promote-password-flow-c81d42`: passed for all canonical writes.
|
||||
- `git diff --check`: passed.
|
||||
- `node --run check:repo`: 10/10 passed after canonical integration.
|
||||
- `node --run check`: passed after canonical integration.
|
||||
- `node --run test:control-plane`: 153/153 passed after canonical integration.
|
||||
- `node --run test:legacy`: 260/260 passed after canonical integration.
|
||||
- `node --run build`: passed after canonical integration.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Restart or redeploy the standard service only under separate explicit authorization before relying on the new backend behavior in the running process.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. The accepted feature candidates were promoted in this integration task.
|
||||
Reference in new issue
Block a user