Security/Config: fix machine-door bind claim, rest.sso path, SSO couplings
Review follow-ups from the SSO/tokens implementation session:
- Security: Advanced - the machine door is not private-network-bound by
default (all interfaces); the always-on protection is the separate
cluster credential, private-network binding is deployment hardening.
Reword the listener note and the "can't even reach it" claim so the
security guarantee rests on the credential, not the default bind.
- Configuration: Advanced - SSO operator files live under the short
resources/rest.sso/ (intentional exception to the FQN <component>
naming), and include the doorway's own signing keystore + SAML.properties.
- Configuration: Advanced - document the two SSO matched-pair couplings
(issuer/audience; signing keypair vs verifying certificate) as
silent-failure traps.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj
Split Security into Security: Basics + Advanced; add Config Tokens/SSO
Concepts:
- Rename Security -> Security: Basics (operational surfaces unchanged).
- New Security: Advanced - the mechanisms behind the surfaces: the token
model (two kinds, fingerprint storage, the two-question check with cache
TTL + write-bypass, admin bootstrap), the machine door (two doors,
private-network listener, shared-secret vs mutual certs), and single
sign-on (SAML contract, login/refresh flow, offline token validation,
pasted-URL browsing), plus ironclad defaults + audit.
Configuration: Advanced - two operator sections:
- Tokens: store on the primary's /app/data, first-boot bootstrap secret,
expiry / switch-off tunables, deployment-choice vs -cfg-<tag> bake.
- Single sign-on: resources/ drop, entityID / IdP-cert / role settings,
gateway signing-cert + allowed-origins.
Sidebar + cross-refs re-pointed: SSO-specific links -> Advanced;
scope/delegation/network links -> Basics.
Sourced from com.metafluent.rest/docs/design.md; property keys deferred to
Configuration: Reference pending the shipped implementation.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aV4rcuYnv4rUf3adqG7gj