Files
flowdeck/docs/V72_Enterprise_SCIM_2FA.md
T
bruno 1706ad1ee9
FlowDeck CI / lint (push) Successful in 1m48s
FlowDeck CI / test (push) Failing after 21m19s
FlowDeck CI / docker (push) Skipped
feat: v7.3.0 — cycle v6.8.0→v7.3.0 (Sites, Search, Automations, Calendar, SCIM, Wiki) + audit A9
- v6.8.0 Sites & Forms publics (migrations 24)
- v6.9.0 Recherche sémantique hybride + Ask AI (migration 25)
- v7.0.0 Automations v2 multi-étapes + Workers sandboxés (migration 26)
- v7.1.0 Calendar sync Google/CalDAV + Meeting Notes (migration 27)
- v7.2.0 Enterprise : SCIM 2.0, 2FA TOTP/passkeys, audit UI, agent approvals (migration 28)
- v7.3.0 Wiki/Teamspaces, verified pages, collab polish, charts, unfurl (migration 29)
- docs V68→V73, ROADMAP/CHANGELOG/WORKLOAD à jour, VERSION 7.3.0
- A9 : flowdeck.db, flowdeck_dev.db, test-commit.md, upload_test.txt et e2e/{node_modules,shots,test-results} désindexés + ignorés (.gitignore/.dockerignore)
2026-09-30 20:02:57 -04:00

2.2 KiB

V7.2.0 — Enterprise Admin : SCIM + 2FA + Audit UI

Statut : 📝 Planifié · Roadmap : ROADMAP.md § v7.2.0 Référence Notion : SCIM, audit log, domain verification, agent permissions/governance. Existant : SSO SAML/OIDC + provisioning + sso_only (v6.7.0), api_audit_log + permission_audit_log + sso_login_history (API seule), SessionManager, PermissionManager.


1. SCIM 2.0 (provisioning auto)

GET|POST /scim/v2/Users, GET|PUT|PATCH|DELETE /scim/v2/Users/{id} (Bearer scim_tokens, admin) : mapping userName→login, emails[0]→email, name→full_name, active→users.is_active. active=false → is_active=0, sessions révoquées, login refusé (401 « suspended ») sauf admin. Groupes IdP → sync_sso_permissions() existant réutilisé.

2. 2FA + passkeys

  • TOTP : users.totp_secret_enc (Fernet), setup QR (otpauth://), vérif au login après password (fenêtre ±1), 10 backup codes (sha256, usage unique).
  • WebAuthn : webauthn_credentials (id, user_id, credential_id, public_key, sign_count) ; login password + key ou passkey seule si passwordless_allowed.
  • Combinable avec sso_only (local password refusé, TOTP conservé si require_2fa=1).

3. Domain claim + audit UI

  • domain_claims (domain UNIQUE, txt_token, verified BOOL, auto_join_role, enforce_sso BOOL) ; vérif DNS TXT ; enforce_sso → login local du domaine redirigé IdP.
  • Settings → Audit : table unifiée (api_audit_log + permission_audit_log + sso_login_history + worker_runs), filtres acteur/ressource/date, export CSV (10k max), rétention 365j (purge scheduler).

4. Gouvernance agents

agent_policies (workspace_id, allowed_tools_json, max_steps, require_approval BOOL) + agent_approvals (action_id, status pending/approved/rejected, approver_id) : si require_approval et outil write → agent.run.approval_requested (webhook + cloche) → exécution après approve, sinon 403. File Settings → Agents.

5. Migrations 28 + tests (~25)

scim_tokens, domain_claims, webauthn_credentials, agent_policies, agent_approvals, users.is_active/totp_secret_enc. Tests : SCIM CRUD + suspend, TOTP ±fenêtre + backup, WebAuthn mock, domain TXT mock, audit filtres/export, policies approve/reject.