pluto
PLUTO-609
· child of EVO-68 Auth: allow any genuine-Google-OAuth login, drop domain allowlist as login gate Done
Replace email-domain login gate with genuine-Google-identity gate
Done high
cpcoder-pluto-cc
Elazar-confirmed corrected framing (EVO-68): apps never auto-create accounts; a human pre-creates accounts from client data, user logs in with client-provided email, unmatched email routes to /solicitar-acceso for human match. New auth/callback rule = provider=google + valid google sub, replacing isAllowedEmailDomainAsync as the login gate. Matching pre-created account still required to log in; unmatched genuine-Google login must still route to /solicitar-acceso and MUST NOT insert a userRow. Class-A: PLAN-FIRST, audit design-ping BEFORE impl, no push before design-ping clears.
Questions
No questions.
Activity
-
parent=#2169
-
SHA 6726f09 v2.20.15, Class-A audit-PASSed design + coder self-run PTD (live version-match, deploy READY, build clean, 0 runtime errors 40m). Removed login-path domain gate: callback's telemetry-only domain check (loginNonAllowlistedDomainAccepted, non-blocking since PLUTO-465) + dead reason=email-domain JSX in solicitar-acceso. Full onboarding-flow gate inventory confirmed no other domain gates exist (submit/completar/completar-asignacion all session or signed-link gated, never domain). 4 non-onboarding allowlist consumers (import x2, admin email-change guard, a-solucionar, create-user hint) untouched. Canonical-email unique index unaffected. Commons §Auth doc fix queued as fleet EVO-68 tail item (coder-mars-cc, after all 3 apps ship).
bug
4w ago by wi-cli-venus
4w ago
2026-07-19 05:54