docs: record simplified password lifecycle

This commit is contained in:
inman committed 2026-09-02 11:23:02 +08:00
1 parent 029c8c6a59
commit ed456e6a5d
7 files changed
+62 -4

No files matched your search

+3 -1
View File
@@ -13,6 +13,7 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- Integration task `20260901-integrate-account-system-7b2f4d` for canonical authorization reconciliation, migrations 015–017, and the authorized standard-panel restart.
- Commit `823d1cb6305077e1743f8783176d2cae3b5aec39` for the aggregate-first leadership platform-operations dashboard and business-safe input/result projections.
- Integration task `20260901-integrate-leadership-dashboard-9e2b6c` for the leadership-dashboard product-definition correction.
- Merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` from feature task `20260902-registration-invalid-params-59f94692`, with canonical promotion by integration task `20260902-promote-password-flow-c81d42`, for non-empty-only password validation and removal of the first-login forced-password-change workflow.
## Current Focus
@@ -29,6 +30,7 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
- 2026-08-31: Confirmed from the supplied production log that attachment correlation succeeded and the failure was private/reserved DNS rejection; removed that rejection for the trusted internal deployment while retaining credential-free HTTPS, DNS pinning, redirect validation, size, timeout, and SHA-256 controls.
- 2026-09-01: Integrated and started the three-role account system on the standard 8786 control plane. Migrations 015–017 added owner/audit/archive state, team-lead dashboard support, and administrator-managed task-route allowlists; the existing account migrated as administrator.
- 2026-09-01: Reframed the leadership dashboard from instruction-history/audit presentation to a platform-running view across tasks, people, input, output, time, type, and completion, with clickable drill-through and no visible technical payload language.
- 2026-09-02: Removed application-level password length limits and the first-login forced-password-change flow while preserving voluntary password changes, administrator resets, session revocation, roles, task ownership, and route authorization.
## In Progress
@@ -56,4 +58,4 @@ Operate the current `0.5.163` extension baseline and the deployed fixed-scope ac
## Last Updated
2026-09-01
2026-09-02
@@ -0,0 +1,51 @@
# Task: Promote simplified password lifecycle
## Identity
- Task ID: 20260902-promote-password-flow-c81d42
- Mode: Integration
- Branch: main
- Worktree: /Users/inmanx/Documents/lwltAPI
- Base commit: 029c8c6a59215cb6c3f8d7f126c4313730b2abb2
- Owner: codex
- Status: Ready for Integration
## Scope
- Promote the accepted password-lifecycle facts from feature task `20260902-registration-invalid-params-59f94692` and merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` into canonical project memory.
- Reconcile `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
- Run the task-aware project-document gate and complete repository verification from a base commit that already contains the source task record and evidence.
## Intent And Constraints
- Record the user's explicit product decision: passwords require a non-empty value but have no application-level length restriction, and first-login forced password changes are disabled.
- Preserve voluntary password change, administrator reset, session revocation, account roles, owner isolation, route grants, audit, dashboard behavior, and ERP safety boundaries.
- Treat the historical `must_change_password` column as compatibility-only; do not add a destructive migration.
- Do not restart or deploy services, mutate live accounts/database rows, access ERP, or send data externally.
## Outcome
- Accepted the source task's promotion candidates without semantic conflict because the user directly confirmed the product behavior.
- Updated `AUTH-001`, the decision index, system overview, business rules, current state, and evidence index.
- Recorded merge commit `029c8c6a59215cb6c3f8d7f126c4313730b2abb2` and this integration task under `Integrated Through`.
- No runtime, database, ERP, external-system, deployment, or service-process state was changed.
## Verification
- Source merge verification: repository check 10/10, control-plane 153/153, legacy 260/260, TypeScript check/build, JavaScript syntax, and diff checks passed on integrated `main`.
- `check_project_docs.py`: passed.
- `check_doc_drift.py --task-id 20260902-promote-password-flow-c81d42`: passed for all canonical writes.
- `git diff --check`: passed.
- `node --run check:repo`: 10/10 passed after canonical integration.
- `node --run check`: passed after canonical integration.
- `node --run test:control-plane`: 153/153 passed after canonical integration.
- `node --run test:legacy`: 260/260 passed after canonical integration.
- `node --run build`: passed after canonical integration.
## Follow-ups
- Restart or redeploy the standard service only under separate explicit authorization before relying on the new backend behavior in the running process.
## Promotion Candidates
- None. The accepted feature candidates were promoted in this integration task.