fix: route Penpot login through shared SSO policy
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
---
|
||||
name: corp-v1-channel-ui-ux
|
||||
description: "Use when operating or synchronizing a Corp v1 project's UI/UX channel. Maintains project frontend design work, Penpot artifacts, design-system decisions, accessibility evidence, and implementation handoffs while correlating verified activity across the project's seven channels."
|
||||
version: 1.2.1
|
||||
version: 1.2.2
|
||||
author: Hermes Agent
|
||||
license: MIT
|
||||
metadata:
|
||||
@@ -138,7 +138,7 @@ For every governed design package:
|
||||
- record material design decisions and review status in project documentation;
|
||||
- use exports only as review aids—never as a replacement for the editable Penpot source.
|
||||
|
||||
If Penpot requires login and the active session is not authenticated, stop at the login wall and request user authentication. Never guess credentials or move design work into an unapproved substitute platform.
|
||||
If Penpot requires login and the active session is not authenticated, first follow the shared Corp v1 SSO policy above using the injected runtime secrets against the verified Penpot origin. If injection is unavailable or authentication is rejected, stop and report only the non-sensitive credential-injection or access blocker. Never guess credentials or move design work into an unapproved substitute platform.
|
||||
|
||||
## Design Package Contract
|
||||
|
||||
|
||||
Reference in New Issue
Block a user