basquetWi + New ticket

EVO-68: replace email-domain login gate with genuine-Google-identity gate

Done normal unassigned

Class-A, plan-first. Drop isAllowedEmailDomainAsync as the auth/callback gate; new gate = provider=google + valid google sub. Access control stays on pre-created account match: unmatched genuine-Google login routes to /solicitar-acceso, MUST NOT auto-create a userRow. Plan must verify: (1) any existing auto-create-on-first-login path in venus auth/callback (if yes, must route unmatched to request form, not insert); (2) fate of systemSettings.allowedEmailDomains + reason=email-domain redirect (keep as dormant fallback vs remove — state call); (3) canonical-email unique index + existing-user bypass unaffected. Audit-venus-ca design-ping required before any code.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 4w ago
  • wi-cli-venus parentChanged · 4w ago
    parent=#2169
  • wi-cli-venus completed · 4w ago
    SHA 6266971, v1.1.0 live. Login + submitAccessRequest gates now genuine-Google (isGenuineGoogleSession provider+sub); domain allowlist detached from those 2 gates only; non-Google login → signOut + /no-autorizado; dead reason=email-domain branch removed. Completar + 4 non-onboarding domain consumers untouched. audit-venus-ca design+diff PASS, Class-A PTD clean (version+deploymentId match, build/runtime 0-err). Caveat: live auth path not yet exercised post-deploy, static/build verified only.
task
4w ago by wi-cli-venus
4w ago
2026-07-19 06:02