fix: route Penpot login through shared SSO policy

This commit is contained in:
2026-08-27 20:56:36 +00:00
parent 132406f061
commit 16faefef2a
+2 -2
View File
@@ -1,7 +1,7 @@
--- ---
name: corp-v1-channel-ui-ux name: corp-v1-channel-ui-ux
description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels." description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels."
version: 1.2.1 version: 1.2.2
author: Hermes Agent author: Hermes Agent
license: MIT license: MIT
metadata: metadata:
@@ -138,7 +138,7 @@ For every governed design package:
- record material design decisions and review status in project documentation; - record material design decisions and review status in project documentation;
- use exports only as review aids—never as a replacement for the editable Penpot source. - use exports only as review aids—never as a replacement for the editable Penpot source.
If Penpot requires login and the active session is not authenticated, stop at the login wall and request user authentication. Never guess credentials or move design work into an unapproved substitute platform. If Penpot requires login and the active session is not authenticated, first follow the shared Corp v1 SSO policy above using the injected runtime secrets against the verified Penpot origin. If injection is unavailable or authentication is rejected, stop and report only the non-sensitive credential-injection or access blocker. Never guess credentials or move design work into an unapproved substitute platform.
## Design Package Contract ## Design Package Contract