v0.97: Gateway admin accounts, employee roster and employee self-service - #101
Merged
Merged
Conversation
- Named administrator accounts at /admin (owner/admin/viewer), password + authenticator (TOTP) or company sign-in; bootstrap token only creates the first owner and can be disabled for API use. - Employee roster (manual or CSV) and personal invitations that lock a computer's identity to one employee; identity source per computer; linking self-reported computers; require-verified mode; offboarding. - /me: each employee sees their computers, the evidence the Gateway holds, who can read it and every recorded read, opened from their own OpenWorkGraph or with company sign-in. - OpenID Connect sign-in (PKCE, nonce, JWKS-verified ID tokens) for admins, employees and invitation confirmation (/join/verify). - Docs, deploy settings and tests.
v0.96: first useful reconstruction without new capture
Preserve the merged first-value activation work from main while retaining the Gateway named-admin, employee-roster, personal-invitation and employee self-service implementation from PR #101. Resolve the overlapping package-data and v0.96 changelog files deliberately.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is the v0.97 enterprise identity release, reconciled onto the already-merged v0.96 first-value activation work. It does not replace or revert the v0.96 activation/history/agent functionality.
The Gateway previously had an admin page but no named administrator identities or employee roster. This PR adds:
/admin;/metransparency view of organization-held evidence and recorded reads;Security invariants added during reconciliation
/me: if the same email exists in more than one organization on one Gateway, generic company sign-in refuses to guess which tenant to open; an organization-specific/device link is required.email_verified: falseis refused. Providers that omit the optional claim are supported only after normal signature/issuer/audience/nonce verification, optional allowed-domain enforcement, and matching a known administrator or roster employee.no-store, and frame denial.Compatibility
docs/CHANGELOG_V096.mdremains the v0.96 activation changelog; this release usesdocs/CHANGELOG_V097.md.Release
All version authorities are aligned to 0.97.0 so, after merge, the release workflow will create a new v0.97.0 release rather than silently leaving the already-published v0.96.0
releases/latestZIP in place.Please merge only after the full exact-head Python matrix, browser JS, Gateway/Postgres container, macOS/Windows packages, Claude MCPB and custom-agent SDK packaging are green.