Closed (fixed)
Project:
FileGate
Version:
1.x-dev
Component:
Documentation
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
31 Jul 2026 at 14:53 UTC
Updated:
31 Jul 2026 at 17:27 UTC
Jump to comment: Most recent
1.3.0 ships high-assurance plain-link (OIDC step-up + FG_AB bridge) and native WebAuthn RP mode. Kernel tests cover contracts (challenge, bridge, invalid tokens, grant HMAC). Full browser + hardware ceremonies are not in CI (normal for WebAuthn/PIV).
GitHub: Wilkes-Liberty/file_gate#37 (implementation / checklist work happens there; this issue is the public dual-venue record).
A repeatable manual E2E checklist (and optional automated browser suite later) that proves:
max_uses / TTL behave.acr, spent one-time link, expired grant, missing credentials, wrong wh/sh.client_cert mode with trusted proxy header.docs/ checklist with environment prerequisites (Keycloak or login.gov-style IdP, YubiKey/platform authenticator, HTTPS origin)None.
None.
Comments
Comment #2
jmcerdaFixed in 1.4.0 (checklist docs/E2E-ASSURANCE.md).
Release: https://www.drupal.org/project/file_gate/releases/1.4.0
GitHub: https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.4.0
Comment #4
jmcerdaComment #5
jmcerdaClosed (fixed): manual E2E checklist (docs/E2E-ASSURANCE.md) shipped in 1.4.0 (GH #37).
https://www.drupal.org/project/file_gate/releases/1.4.0
https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.4.0
Comment #6
jmcerdaConfirm Closed (fixed). Work shipped; removing from Open queue.