feat: approval-gated legacy identity remediation tooling - #117
Open
felixgateru wants to merge 15 commits into
Open
felixgateru wants to merge 15 commits into
felixgateru wants to merge 15 commits into
Conversation
…ability so it matches the migration-seeded database contract Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ady hit the undeclared api_endpoint applicability error Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
… verified email-change flow Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…confirm flow Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…contracts Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ries Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ontracts Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…port Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…hQL mutations Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…or runbook Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
…ion mutations Signed-off-by: Felix Gateru <felix.gateru@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Depends on #116 (report) and #115 (email-change flow): stacked on both, so this diff includes their commits until they merge.
Fix
Three platform-admin-only GraphQL mutations, each targeting exactly one operator-identified row — no bulk "fix everything" entry point — requiring a non-empty evidence/reason string recorded verbatim in
audit_logs, and idempotent (a repeated or resumed call is a safe no-op):recordAdministratorAssistedEmailVerification(entityId, evidence)— setsentity_emails.verified_aton the strength of evidence gathered outside Atom (a support ticket, an identity check). Atom cannot verify the evidence itself; it only requires the caller to state it.quarantineOauthLink(entityId, provider, subject, reason)— soft-disables a suspicious link via a newoauth_identities.quarantined_atcolumn (migration003), preserving the row for audit.upsert_oauth_identity's existing-link lookup now rejects a quarantined link outright — it can never re-authenticate or be silently refreshed by a fresh callback.revokeOauthLink(entityId, provider, subject, reason)— hard, unrecoverable delete for links already confirmed unjustified.Publishes the existing frozen
entity.updateevent rather than a new event name (v1 event names are frozen).runbooks/legacy-identity-recovery.mdis the operator procedure: backup first, run the report, triage bypendingTokens(a self-service path may already be in flight), remediate one row at a time, verify by re-running the report, and documented rollback boundaries for what each mutation can't undo on its own.Tests
upsert_oauth_identityCompletes #110 (workstream B).