Ticket: AUTH-T94 · Epic: E13 Testing & QA · Phase: Phase 1 — Core auth, sessions, SSO (MVP)
Priority: High · Estimate: 5 points · Labels: epic:testing, phase:1, testing, auth-core
Depends on:
Test harness: vitest, Neon test branch, factories, and test mailer #105 — AUTH-T93 Test harness: vitest, Neon test branch, factories, and test mailer
Email + password sign-in and self-sign-up restricted to northeastern.edu #29 — AUTH-T17 Email + password sign-in and self-sign-up restricted to northeastern.edu
Email verification for self-sign-up with resend limits #30 — AUTH-T18 Email verification for self-sign-up with resend limits
Password reset flow #31 — AUTH-T19 Password reset flow
Session lifetime: 30-day sliding, 90-day absolute cap, no cookie cache #39 — AUTH-T27 Session lifetime: 30-day sliding, 90-day absolute cap, no cookie cache
Escalating account lockout with emailed unlock and known-device exemption #76 — AUTH-T64 Escalating account lockout with emailed unlock and known-device exemption
End-to-end (HTTP-level) tests: sign-up + verify + login; domain rejection; wrong password; lockout and unlock; forgot/reset including session revocation; invite acceptance; deactivated user; session sliding and absolute expiry; logout and sign-out-everywhere; re-auth freshness; rate-limit responses with the fake limiter.
Acceptance criteria
Generated from the SGAuth design (docs/sgauth-design in SGAOperations/auth). SGAuth is built on Neon and does not use Supabase.
Ticket: AUTH-T94 · Epic: E13 Testing & QA · Phase: Phase 1 — Core auth, sessions, SSO (MVP)
Priority: High · Estimate: 5 points · Labels: epic:testing, phase:1, testing, auth-core
Depends on:
End-to-end (HTTP-level) tests: sign-up + verify + login; domain rejection; wrong password; lockout and unlock; forgot/reset including session revocation; invite acceptance; deactivated user; session sliding and absolute expiry; logout and sign-out-everywhere; re-auth freshness; rate-limit responses with the fake limiter.
Acceptance criteria
Generated from the SGAuth design (docs/sgauth-design in SGAOperations/auth). SGAuth is built on Neon and does not use Supabase.