58 lines
4.0 KiB
Markdown
58 lines
4.0 KiB
Markdown
# Task: Integrate simplified account password flow
|
|
|
|
## Identity
|
|
|
|
- Task ID: 20260902-integrate-password-flow-b73c91
|
|
- Mode: Integration
|
|
- Branch: main
|
|
- Worktree: /Users/inmanx/Documents/lwltAPI
|
|
- Base commit: e530b7a3489c8f2be2f15f69de2149658aaa8ca3
|
|
- Owner: codex
|
|
- Status: Ready for Integration
|
|
|
|
## Scope
|
|
|
|
- Integrate feature task `20260902-registration-invalid-params-59f94692` commits `203bfb3` and `df65e9f` into the current `main` branch after the dashboard tasks released the main worktree.
|
|
- Reconcile overlapping account UI and authorization tests while preserving the subsequently integrated dashboard layout and ranking-bar behavior.
|
|
- Run the complete repository verification gates on the merged result.
|
|
- Hand canonical promotion to a follow-on Integration Gate whose base commit already contains the source task record and supporting evidence, as required by the task-aware drift checker.
|
|
|
|
## Intent And Constraints
|
|
|
|
- Password entry points require a non-empty value but impose no application-level length restriction.
|
|
- Remove first-login forced password changes from the UI, API/session contract, and authorization gates; retain voluntary password change, administrator reset, and session revocation.
|
|
- Keep the historical `must_change_password` column compatibility-only and clear it on password writes rather than adding a destructive migration.
|
|
- Preserve all current dashboard changes already on `main`, account roles, owner isolation, route authorization, audit, and ERP safety boundaries.
|
|
- The user authorized merging to `main`; service restart, deployment, live account/database mutation, and ERP access remain out of scope.
|
|
|
|
## Outcome
|
|
|
|
- Merged feature commits `203bfb3246f70beb82f7759752d828cfc8259060` and `df65e9f5174b843de9722dfddcba172888f2b557` into the current `main` history without conflicts.
|
|
- Confirmed that the three subsequent dashboard commits and their ranking-bar UI remain present after the merge.
|
|
- Account creation, login, administrator reset, and self-service change now accept any non-empty password and impose no application-level length limit.
|
|
- Removed the first-login forced-change UI option, response/session flag, account badge, and read/mutation gates. Voluntary password change, administrator reset, session revocation, roles, owner isolation, route grants, and audit behavior remain intact.
|
|
- Kept canonical project-memory edits out of this source merge. The first drift run correctly identified that source task-owned records landed after this task's base commit; canonical promotion continues under task `20260902-promote-password-flow-c81d42` from the completed merge commit.
|
|
- No service restart, deployment, live account/database mutation, ERP access, or external delivery was performed.
|
|
|
|
## Verification
|
|
|
|
- Feature-worktree verification: account-form 4/4, focused authorization 8/8, repository check 10/10, control-plane 153/153, legacy 260/260, TypeScript check/build, JavaScript syntax, and diff check all passed.
|
|
- Integrated `main` `node --run check:repo`: 10/10 passed.
|
|
- Integrated `main` `node --run check`: passed.
|
|
- Integrated `main` `node --run test:control-plane`: 153/153 passed.
|
|
- Integrated `main` `node --run test:legacy`: 260/260 passed.
|
|
- Integrated `main` `node --run build`: passed.
|
|
- Integrated `main` `node --check LianSyn-platform/app.js`: passed.
|
|
- `git diff --check`: passed.
|
|
- `check_project_docs.py`: passed.
|
|
- The initial task-aware drift check correctly blocked canonical integration because the feature task record and evidence entered after this task's base commit. The check was not bypassed; source merge and canonical promotion were split so the follow-on integration task starts from the merged source commit.
|
|
|
|
## Follow-ups
|
|
|
|
- Continue canonical promotion under integration task `20260902-promote-password-flow-c81d42`.
|
|
- Restart or redeploy the standard service only under separate explicit authorization before relying on the new backend behavior in the running process.
|
|
|
|
## Promotion Candidates
|
|
|
|
- Carry the source feature task's accepted password-lifecycle candidates into integration task `20260902-promote-password-flow-c81d42`.
|