chore(kanidm): declare a standing test account for passkey-page checks #484
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!484
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/test-passkey-check-user"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Why
ADR 0038 conceals identity fields with CSS. The
health-checkrole blocks a Forgejo upgrade until those surfaces are re-verified against the new tag, and one of them is the Kanidm passkey-enrolment page (/ui/reset?token=…). That page is the only check that catches a selector hiding too much — the direction that broke passkey enrolment entirely on 2026-08-04 when.row:has(input[name="name"])was unscoped.Reaching that page needs a live credential-reset token, which needs an account.
forgejo_userswas empty, so the check could only be run by issuing a reset link against a real person's account.What
One declared user:
forgejo_usersis the single source of truth for both the Kanidm person and the Forgejo account (vars.ymlheader,kanidm-state.json.j2:5), so this is the only sanctioned route. The repo has no separate test-account concept and this is an ordinary user in every respect.role: "user"keeps it out offorgejo_admins. The address needs no mailbox; the domain has a catch-all.Quota and seat impact
reconciler_user_exemptis derived fromforgejo_users(roles/reconciler/defaults/main.yml:90), and the exempt branch is evaluated before the tier branches inprojection.tsclassifyUser(), so the account gets the unlimited first-party group rather than the paid 10 GiB one.tier_basic, becausekanidm-state.json.j2:10layers everyforgejo_usersentry into that group.roles/reconciler/defaults/main.yml:23labelstier_basic"paid seat". The Forgejo-side quota is unaffected per the point above, but anything outside this repo that countstier_basicmembership as a paying user would count this account. Worth confirming against the billing side before the seat count is trusted.After merge
Provisioning is deliberately not a full
site.ymlrun:health-checkis taggedalwaysand sits at the end of the play, so a full run would apply the pending Forgejo 16.0.5 upgrade and only then fail the concealment gate. Scope it:That creates the Kanidm person and prints one reset link (TTL 24 h). The Forgejo account is not created by a kanidm-tagged run and is not needed for the passkey check; it lands on the next full apply.
Every later check mints its own token, no playbook:
Notes
ansible-lintpasses (production profile),site.yml --syntax-checkpasses.