Skip to content

docs(backlog): file PKG-3 + AUTH-1 as P1#674

Merged
remyluslosius merged 2 commits into
mainfrom
docs/backlog-pkg3-auth1
Jun 25, 2026
Merged

docs(backlog): file PKG-3 + AUTH-1 as P1#674
remyluslosius merged 2 commits into
mainfrom
docs/backlog-pkg3-auth1

Conversation

@remyluslosius

Copy link
Copy Markdown
Contributor

Adds two P1 backlog rows (and a new Security / Auth section) capturing this session's diagnoses:

Docs-only.

…n timeouts) as P1

PKG-3: hardened systemd unit leaves the Kensa rollback store unwritable ->
remediation 'not wired' on every packaged install (fix in #673).
AUTH-1: idle + absolute session timeouts not effectively enforced for the
browser (polling slides the window; refresh-cookie re-mints sessions; no
client-side idle timer). Layered fix; client idle timer is slice 1 (in progress).
@remyluslosius remyluslosius merged commit 7d80298 into main Jun 25, 2026
12 checks passed
@remyluslosius remyluslosius deleted the docs/backlog-pkg3-auth1 branch June 25, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant