--- phase: 02-authentication-multi-tenancy plan: 05 type: execute wave: 4 depends_on: - 02-02 - 02-03 - 02-04 files_modified: [] autonomous: false requirements: - AUTH-01 - AUTH-02 - AUTH-03 - AUTH-04 - AUTH-05 - AUTH-06 - TNNT-01 - TNNT-02 - TNNT-03 must_haves: truths: - "All phase 2 success criteria verified by human observation" - "Login flow works end-to-end in browser" - "Admin can manage users and tenants" - "LDAP sync functional against test server" - "Tenant data isolation confirmed" artifacts: [] key_links: [] --- Visual and functional verification of the complete Phase 2 authentication and multi-tenancy system. Human confirms all success criteria from the ROADMAP are met through browser-based testing. Purpose: Ensure the entire auth and multi-tenancy vertical slice works as expected before marking Phase 2 complete. Output: Verified phase completion or issue list for gap closure. @$HOME/.claude/gsd-core/workflows/execute-plan.md @$HOME/.claude/gsd-core/templates/summary.md @.planning/ROADMAP.md @.planning/phases/02-authentication-multi-tenancy/02-CONTEXT.md @.planning/phases/02-authentication-multi-tenancy/02-01-SUMMARY.md @.planning/phases/02-authentication-multi-tenancy/02-02-SUMMARY.md @.planning/phases/02-authentication-multi-tenancy/02-03-SUMMARY.md @.planning/phases/02-authentication-multi-tenancy/02-04-SUMMARY.md ## Artifacts this phase produces No new artifacts. This plan verifies existing artifacts from Plans 02-01 through 02-04. Complete Phase 2: Authentication and Multi-Tenancy system including: - Split-screen login page with Tessera branding (D-01) - JWT httpOnly cookie session with 30-day expiry (D-02) - Password reset via email with MailHog (D-03) - Force password change on first login (D-06) - Initial admin seeded from Docker ENV (D-05, D-07) - Three-role RBAC: Super-Admin, Admin, User (D-12) - User CRUD admin page (AUTH-02) - Tenant management for Super-Admin (D-10, TNNT-02) - PostgreSQL RLS tenant data isolation (D-11, TNNT-01) - LDAP sync with configurable field mapping (AUTH-06, D-14..D-18) Start the full stack: docker compose -f docker-compose.yml -f docker-compose.dev.yml up -d **1. Login Flow (AUTH-03, D-01, D-04)** - Open http://localhost:3000 -- should redirect to /login - Verify login page is split-screen: branding left (yellow), form right - Verify NO sidebar or header on login page - Login with admin / admin123 - Verify redirect to dashboard - Verify header shows admin user avatar/initial - Verify sidebar footer shows admin name and role **2. Session Persistence (AUTH-04, D-02)** - Refresh the browser page - Verify you are still logged in (not redirected to login) - Open browser dev tools -> Application -> Cookies - Verify "session" cookie exists with httpOnly flag **3. User Management (AUTH-02, D-12)** - Navigate to /admin/users (or click "Benutzer" in sidebar) - Verify user table shows the admin account - Create a new user with role "User" - Verify user appears in table - Edit the user (change display name) - Verify changes reflected - Try creating a user with role "Admin" **4. Tenant Management (TNNT-02, D-10)** - Navigate to /admin/tenants (or click "Mandanten" in sidebar) - Verify "Default" tenant is listed - Create a new tenant - Verify it appears in the table **5. Logout** - Click logout button in header - Verify redirect to /login - Try navigating to /admin/users directly -- should redirect to /login **6. Password Reset (D-03)** - On login page, click "Passwort vergessen" link - Enter admin email, submit - Open MailHog at http://localhost:8025 - Verify password reset email received - Click the reset link in the email - Set new password, verify success **7. Force Password Change (D-06)** - (If TESSERA_FORCE_CHANGE was set to true for a user) - Login as that user -- should be redirected to change password page - Change password, verify normal access afterward **8. LDAP Sync (AUTH-06, D-14..D-18)** - Navigate to /admin/ldap - Verify LDAP configuration form exists with all fields - Verify default field mappings are shown (displayName, mail, sAMAccountName) - If OpenLDAP is running with test data: - Configure connection and click "Verbindung testen" - Click "LDAP synchronisieren" and verify result counts **9. i18n** - Switch language to English (locale switcher in sidebar) - Verify all auth-related pages show English text - Switch back to German **10. Theme** - Toggle to dark mode - Verify login page and admin pages render correctly in dark mode Type "approved" if all checks pass, or describe any issues found ## Trust Boundaries No new trust boundaries -- this plan verifies existing ones. ## STRIDE Threat Register No new threats -- this plan verifies existing mitigations. Human verifies all ROADMAP Phase 2 success criteria: 1. Initial admin account is created automatically from Docker environment variables on first startup 2. Admin can create, edit, and delete user accounts with role assignment (Admin/User) 3. User can log in and log out, with session surviving browser refresh 4. Admin can create and manage tenants, and each user's data is isolated per tenant via RLS 5. Users can be imported from an LDAP/AD directory - All 5 ROADMAP success criteria visually confirmed - All 18 locked decisions (D-01..D-18) implemented as specified - No blocking issues remain Create `.planning/phases/02-authentication-multi-tenancy/02-05-SUMMARY.md` when done