Skip to content

P15 — Authentication, OAuth and Account #37

Description

@Techshrr

P15 — Authentication, OAuth and Account

Parent tracker: #1
PR: #38merged
Base integration commit: 9258cb0f3f913b37b03aa8cf3c2938711314d3aa (P14)
Branch: develop/p15-authentication-oauth-account
Product-contract authority: 9ba89a42281709087b40cdcf0cb2eebd54952a99
Pre-sign implementation SHA: 1625c01164cecd1a5060997265f5c1fe004ca0ee
Signed exact HEAD: 6f39d87f1d94f71590fd79d4551cdd1cea652a76
Integration commit: dd70eacf02d4dd79fe82063f3d43610ab11885e8

Final status

COMPLETED / SIGNED EXACT-HEAD CLOSURE PASS / MERGED

  • Frozen cases: P15-T001..P15-T029
  • P15-T001..P15-T029: PASS on signed exact HEAD
  • T028 exact-head coherence: PASS
  • T029 accountable closure: PASS
  • closure.json: status=PASS, phase=signed, merge_authoritative=true
  • Input evidence: 28/28
  • Required affected exact-head matrix: 50/50 SUCCESS
  • P0: 0
  • P1: 0
  • DECISION REQUIRED: 0

Signed closure authority

  • Final closure run: 32931945354
  • Closure artifact: 9593689993
  • Closure digest: sha256:5a43c87ea26f86081523d371de260e100a20c5c05b3581f48223fb70e68cd233
  • T028 artifact: 9593683987
  • T028 digest: sha256:7ce9b27d7d35dd1895f352b5b87a5d5f2c3836d73df53ee1fad705349077359c
  • Signed-head contract guard artifact: 9593504107
  • Signed-head contract guard digest: sha256:eb03fda16468c9d2867a8a51ec6205d437e75c0af9066083e88363aad8fe8e7e

The signed child is exactly one commit after reviewed pre-sign implementation SHA 1625c01164cecd1a5060997265f5c1fe004ca0ee and changes only artifacts/v10/P15/review.md. The signed revision itself reran all seven P15 producer workflows, T028 and the complete required 50-workflow affected matrix before T029 became merge-authoritative.

Closed P15 ownership

  • CAP-AUTH P15 contribution: complete.
  • CAP-OAUTH P15 contribution: complete.
  • Authentication-facing CAP-TURNSTILE contribution: complete; later P17 ownership remains separate.
  • Server-side credential/session authority, verification/recovery/login-email grants, CSRF/Origin/rate controls and account-enumeration-safe recovery: complete.
  • OAuth providers are exactly google, facebook, github, qq, wechat, rainbow; state/PKCE/handoff/social registration and connected-account bind/unbind: complete.
  • Account settings /app/settings/profile, /app/settings/security, /app/settings/sessions, /app/settings/connected-accounts: complete.
  • Auth route, Workspace account and Admin OAuth browser authority: complete.
  • P14 mail queue/template/native-mailworker authority remains inherited; P15 introduced no parallel SMTP authority.
  • AUTH-INVITE remains P12-owned.
  • Administrator/role/permission lifecycle remains P17-owned.

Handoff

P16 — Trust, Destination Risk and Abuse — is now active under Issue #39 / Draft PR #40 using integration base dd70eacf02d4dd79fe82063f3d43610ab11885e8. P16 must inherit this signed P15 authentication/OAuth/account authority without reinterpretation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions