Files
2026-07-13 19:45:53 +08:00

2.2 KiB

ADDED Requirements

Requirement: Cloud operator sessions are the only human API authentication path

The system SHALL authorize human Cloud API operations through persistent Cloud user sessions and SHALL not require configured static bearer credentials for production startup or normal Console operation.

Scenario: Production starts without credential JSON

  • WHEN the Cloud API starts in production with a current database schema and no configured public, Host, or enrollment credential JSON
  • THEN the application starts, exposes health and authentication routes, and rejects unauthenticated protected API requests

Scenario: Signed-in operator uses a protected API route

  • WHEN an enabled Cloud user has a valid session and calls an operation allowed by the user's role scopes
  • THEN the operation is authorized without an Authorization bearer header

Requirement: The Console contains no token or user-directory management surface

The Console SHALL offer login, logout, current-account display, and password change, and SHALL not render bearer-token controls, token persistence, Users navigation, or user-management forms.

Scenario: Unauthenticated operator opens the Console

  • WHEN no valid user session exists
  • THEN the Console presents the username/password login flow without an API token alternative

Scenario: Administrator opens the Console

  • WHEN an administrator signs in
  • THEN the Console presents normal authorized operational views but no user-directory navigation or account lifecycle form

Requirement: Account provisioning and recovery remain interactive administration operations

The system SHALL retain interactive, non-echoed administration CLI commands to create, reset, enable, and revoke Cloud user accounts without accepting passwords through Compose configuration or command-line arguments.

Scenario: Initial administrator is created after deployment

  • WHEN an operator runs device-cloud-admin users create against the migrated Cloud database and completes the password prompts
  • THEN an enabled administrator account is created without a deployment token or plaintext password in process arguments