docs(02): create phase 2 authentication & multi-tenancy plans
5 plans across 4 waves covering all 9 requirements (AUTH-01..06, TNNT-01..03) and 18 locked decisions (D-01..D-18): - Plan 01 (W1): Backend auth foundation with Prisma schema, RLS, JWT, admin seed - Plan 02 (W2): Frontend auth flow, login page, user/tenant CRUD admin pages - Plan 03 (W2): SUS package verification, password reset, force-change interceptor - Plan 04 (W3): LDAP sync service, per-tenant config, field mapping, admin UI - Plan 05 (W4): Visual verification of complete auth and multi-tenancy system Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,176 @@
|
||||
---
|
||||
phase: 02-authentication-multi-tenancy
|
||||
plan: 05
|
||||
type: execute
|
||||
wave: 4
|
||||
depends_on:
|
||||
- 02-02
|
||||
- 02-03
|
||||
- 02-04
|
||||
files_modified: []
|
||||
autonomous: false
|
||||
requirements:
|
||||
- AUTH-01
|
||||
- AUTH-02
|
||||
- AUTH-03
|
||||
- AUTH-04
|
||||
- AUTH-05
|
||||
- AUTH-06
|
||||
- TNNT-01
|
||||
- TNNT-02
|
||||
- TNNT-03
|
||||
must_haves:
|
||||
truths:
|
||||
- "All phase 2 success criteria verified by human observation"
|
||||
- "Login flow works end-to-end in browser"
|
||||
- "Admin can manage users and tenants"
|
||||
- "LDAP sync functional against test server"
|
||||
- "Tenant data isolation confirmed"
|
||||
artifacts: []
|
||||
key_links: []
|
||||
---
|
||||
|
||||
<objective>
|
||||
Visual and functional verification of the complete Phase 2 authentication and multi-tenancy system. Human confirms all success criteria from the ROADMAP are met through browser-based testing.
|
||||
|
||||
Purpose: Ensure the entire auth and multi-tenancy vertical slice works as expected before marking Phase 2 complete.
|
||||
|
||||
Output: Verified phase completion or issue list for gap closure.
|
||||
</objective>
|
||||
|
||||
<execution_context>
|
||||
@$HOME/.claude/gsd-core/workflows/execute-plan.md
|
||||
@$HOME/.claude/gsd-core/templates/summary.md
|
||||
</execution_context>
|
||||
|
||||
<context>
|
||||
@.planning/ROADMAP.md
|
||||
@.planning/phases/02-authentication-multi-tenancy/02-CONTEXT.md
|
||||
@.planning/phases/02-authentication-multi-tenancy/02-01-SUMMARY.md
|
||||
@.planning/phases/02-authentication-multi-tenancy/02-02-SUMMARY.md
|
||||
@.planning/phases/02-authentication-multi-tenancy/02-03-SUMMARY.md
|
||||
@.planning/phases/02-authentication-multi-tenancy/02-04-SUMMARY.md
|
||||
</context>
|
||||
|
||||
## Artifacts this phase produces
|
||||
|
||||
No new artifacts. This plan verifies existing artifacts from Plans 02-01 through 02-04.
|
||||
|
||||
<tasks>
|
||||
|
||||
<task type="checkpoint:human-verify" gate="blocking">
|
||||
<what-built>
|
||||
Complete Phase 2: Authentication and Multi-Tenancy system including:
|
||||
- Split-screen login page with Tessera branding (D-01)
|
||||
- JWT httpOnly cookie session with 30-day expiry (D-02)
|
||||
- Password reset via email with MailHog (D-03)
|
||||
- Force password change on first login (D-06)
|
||||
- Initial admin seeded from Docker ENV (D-05, D-07)
|
||||
- Three-role RBAC: Super-Admin, Admin, User (D-12)
|
||||
- User CRUD admin page (AUTH-02)
|
||||
- Tenant management for Super-Admin (D-10, TNNT-02)
|
||||
- PostgreSQL RLS tenant data isolation (D-11, TNNT-01)
|
||||
- LDAP sync with configurable field mapping (AUTH-06, D-14..D-18)
|
||||
</what-built>
|
||||
<how-to-verify>
|
||||
Start the full stack:
|
||||
docker compose -f docker-compose.yml -f docker-compose.dev.yml up -d
|
||||
|
||||
**1. Login Flow (AUTH-03, D-01, D-04)**
|
||||
- Open http://localhost:3000 -- should redirect to /login
|
||||
- Verify login page is split-screen: branding left (yellow), form right
|
||||
- Verify NO sidebar or header on login page
|
||||
- Login with admin / admin123
|
||||
- Verify redirect to dashboard
|
||||
- Verify header shows admin user avatar/initial
|
||||
- Verify sidebar footer shows admin name and role
|
||||
|
||||
**2. Session Persistence (AUTH-04, D-02)**
|
||||
- Refresh the browser page
|
||||
- Verify you are still logged in (not redirected to login)
|
||||
- Open browser dev tools -> Application -> Cookies
|
||||
- Verify "session" cookie exists with httpOnly flag
|
||||
|
||||
**3. User Management (AUTH-02, D-12)**
|
||||
- Navigate to /admin/users (or click "Benutzer" in sidebar)
|
||||
- Verify user table shows the admin account
|
||||
- Create a new user with role "User"
|
||||
- Verify user appears in table
|
||||
- Edit the user (change display name)
|
||||
- Verify changes reflected
|
||||
- Try creating a user with role "Admin"
|
||||
|
||||
**4. Tenant Management (TNNT-02, D-10)**
|
||||
- Navigate to /admin/tenants (or click "Mandanten" in sidebar)
|
||||
- Verify "Default" tenant is listed
|
||||
- Create a new tenant
|
||||
- Verify it appears in the table
|
||||
|
||||
**5. Logout**
|
||||
- Click logout button in header
|
||||
- Verify redirect to /login
|
||||
- Try navigating to /admin/users directly -- should redirect to /login
|
||||
|
||||
**6. Password Reset (D-03)**
|
||||
- On login page, click "Passwort vergessen" link
|
||||
- Enter admin email, submit
|
||||
- Open MailHog at http://localhost:8025
|
||||
- Verify password reset email received
|
||||
- Click the reset link in the email
|
||||
- Set new password, verify success
|
||||
|
||||
**7. Force Password Change (D-06)**
|
||||
- (If TESSERA_FORCE_CHANGE was set to true for a user)
|
||||
- Login as that user -- should be redirected to change password page
|
||||
- Change password, verify normal access afterward
|
||||
|
||||
**8. LDAP Sync (AUTH-06, D-14..D-18)**
|
||||
- Navigate to /admin/ldap
|
||||
- Verify LDAP configuration form exists with all fields
|
||||
- Verify default field mappings are shown (displayName, mail, sAMAccountName)
|
||||
- If OpenLDAP is running with test data:
|
||||
- Configure connection and click "Verbindung testen"
|
||||
- Click "LDAP synchronisieren" and verify result counts
|
||||
|
||||
**9. i18n**
|
||||
- Switch language to English (locale switcher in sidebar)
|
||||
- Verify all auth-related pages show English text
|
||||
- Switch back to German
|
||||
|
||||
**10. Theme**
|
||||
- Toggle to dark mode
|
||||
- Verify login page and admin pages render correctly in dark mode
|
||||
</how-to-verify>
|
||||
<resume-signal>Type "approved" if all checks pass, or describe any issues found</resume-signal>
|
||||
</task>
|
||||
|
||||
</tasks>
|
||||
|
||||
<threat_model>
|
||||
## Trust Boundaries
|
||||
|
||||
No new trust boundaries -- this plan verifies existing ones.
|
||||
|
||||
## STRIDE Threat Register
|
||||
|
||||
No new threats -- this plan verifies existing mitigations.
|
||||
</threat_model>
|
||||
|
||||
<verification>
|
||||
Human verifies all ROADMAP Phase 2 success criteria:
|
||||
1. Initial admin account is created automatically from Docker environment variables on first startup
|
||||
2. Admin can create, edit, and delete user accounts with role assignment (Admin/User)
|
||||
3. User can log in and log out, with session surviving browser refresh
|
||||
4. Admin can create and manage tenants, and each user's data is isolated per tenant via RLS
|
||||
5. Users can be imported from an LDAP/AD directory
|
||||
</verification>
|
||||
|
||||
<success_criteria>
|
||||
- All 5 ROADMAP success criteria visually confirmed
|
||||
- All 18 locked decisions (D-01..D-18) implemented as specified
|
||||
- No blocking issues remain
|
||||
</success_criteria>
|
||||
|
||||
<output>
|
||||
Create `.planning/phases/02-authentication-multi-tenancy/02-05-SUMMARY.md` when done
|
||||
</output>
|
||||
Reference in New Issue
Block a user