--- title: "3DARCH-FT-9 — Enterprise sign-in and session continuity" description: "Enable a user to enter through enterprise SSO, remain signed in through token refresh, and return to sign-in when the session cannot be recovered." --- # Enterprise sign-in and session continuity | Feature | Parent Epic | Delivery status | Status source | Owner | Approved for Solution | |---|---|---|---|---|---| | `3DARCH-FT-9` | [3DARCH-EP-2 — Secure Access and Personal Setup](../../3darch-ep-2.md) | `IN_BACKLOG` | `EXACT` | 3D Architecture Wizzard team | No | ## Description Enable a user to enter through enterprise SSO, remain signed in through token refresh, and return to sign-in when the session cannot be recovered. ## User or operator problem Enterprise users need trusted access that survives normal token expiry without separate workplace credentials. ## Expected value Provides secure session continuity and a single enterprise identity boundary for protected HTTP and real-time access. ## Scope Includes enterprise OIDC redirect/callback, user upsert, protected cookies, token refresh, request recovery, and authenticated socket admission. ### Exclusions - Administrator access, account recovery, display-name editing, and unwired self-service logout are excluded. ## Acceptance outcomes - [ ] Successful SSO creates or updates the user and returns the user to the workplace. - [ ] Access and refresh credentials remain in protected cookies. - [ ] Expired access is refreshed once and queued requests resume after recovery. - [ ] Authenticated real-time connections reject invalid or duplicate sessions safely. ## Dependencies - [3DARCH-FT-8 — Package, deploy, and health-check workplace services](../../3darch-ep-1/features/3darch-ft-8.md) ## Risks - Duplicate-session handling redirects to a hard-coded legacy location and self-service sign-out is not wired in the client. ## Human approval Linas approved this Feature for documentation on 2026-09-02T10:40:43.220Z. It is **not Approved for Solution** and has no implementation approval. - [Documentation decision](https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201) ## Delivery status evidence The Feature was separately registered at `IN_BACKLOG` as an accepted catalogue boundary. This records backlog retention, not design or delivery progress. - Event: Catalogue registration - Actor and authority: Linas — Human project team member - Reason: The Feature catalogue was accepted for governed documentation and retained in the backlog. - [Status evidence](https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201) ## Architecture traceability - Requirements: none derived. - Readiness: Not started. Architecture solution work must not begin until a separate human **Approved for Solution** decision is recorded. ## Tasks [Review the Tasks group](./3darch-ft-9/tasks.md). No canonical implementation Tasks have been defined. ## Original source - [Discord – Scope – Linas: original Feature request](https://discord.com/channels/1518726359512387766/1543925247361814568/1544647879111483562) - [Discord – Scope – Linas: proceed with documented mapping](https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201) ### Legacy implementation evidence The Feature boundary was mined from legacy revision `c0ced47ecaf4426f47e5c2e4868677f7144b951a`. - [`apps/singularity/src/routes/auth.routes.ts`](https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/routes/auth.routes.ts) - [`apps/singularity/src/config/auth.config.ts`](https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/config/auth.config.ts) - [`apps/nebula/src/hooks/useAuthRefresh.ts`](https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/nebula/src/hooks/useAuthRefresh.ts) - [`apps/nebula/src/api.ts`](https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/nebula/src/api.ts) - [`apps/singularity/src/socket-server/index.ts`](https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/socket-server/index.ts)