{ "id": "3DARCH-FT-9", "type": "Feature", "title": "Enterprise sign-in and session continuity", "epic_id": "3DARCH-EP-2", "description": "Enable a user to enter through enterprise SSO, remain signed in through token refresh, and return to sign-in when the session cannot be recovered.", "user_problem": "Enterprise users need trusted access that survives normal token expiry without separate workplace credentials.", "expected_value": "Provides secure session continuity and a single enterprise identity boundary for protected HTTP and real-time access.", "scope": "Includes enterprise OIDC redirect/callback, user upsert, protected cookies, token refresh, request recovery, and authenticated socket admission.", "exclusions": [ "Administrator access, account recovery, display-name editing, and unwired self-service logout are excluded." ], "acceptance_outcomes": [ "Successful SSO creates or updates the user and returns the user to the workplace.", "Access and refresh credentials remain in protected cookies.", "Expired access is refreshed once and queued requests resume after recovery.", "Authenticated real-time connections reject invalid or duplicate sessions safely." ], "status": "IN_BACKLOG", "status_source": "EXACT", "blocked": false, "blocked_reason": null, "owner": "3D Architecture Wizzard team", "dependencies": [ "3DARCH-FT-8" ], "risks": [ "Duplicate-session handling redirects to a hard-coded legacy location and self-service sign-out is not wired in the client." ], "required_tasks": [], "approval": { "approved_for_solution": false, "approved_for_solution_by": null, "approved_for_solution_at": null, "conditions": [], "evidence_url": null, "approved_for_implementation": false, "approved_for_implementation_by": null, "approved_for_implementation_at": null, "implementation_conditions": [], "implementation_evidence_url": null }, "catalogue_decision": { "decision": "Approved for documentation", "decided_by": "Linas", "decided_at": "2026-09-02T10:40:43.220Z", "evidence_url": "https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201", "conditions": [ "Documentation approval does not grant Approved for Solution or implementation approval." ] }, "sources": [ { "label": "Discord – Scope – Linas: original Feature request", "url": "https://discord.com/channels/1518726359512387766/1543925247361814568/1544647879111483562" }, { "label": "Discord – Scope – Linas: proceed with documented mapping", "url": "https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201" } ], "legacy_revision": "c0ced47ecaf4426f47e5c2e4868677f7144b951a", "legacy_evidence": [ { "path": "apps/singularity/src/routes/auth.routes.ts", "url": "https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/routes/auth.routes.ts" }, { "path": "apps/singularity/src/config/auth.config.ts", "url": "https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/config/auth.config.ts" }, { "path": "apps/nebula/src/hooks/useAuthRefresh.ts", "url": "https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/nebula/src/hooks/useAuthRefresh.ts" }, { "path": "apps/nebula/src/api.ts", "url": "https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/nebula/src/api.ts" }, { "path": "apps/singularity/src/socket-server/index.ts", "url": "https://gitea.lego-cloud.eu/corp-v1-3darch-legacy/corp-v1-3darch-legacy/src/commit/c0ced47ecaf4426f47e5c2e4868677f7144b951a/apps/singularity/src/socket-server/index.ts" } ], "architecture_traceability": { "requirements": [], "readiness": "Not started" }, "release_evidence": [], "last_transition": { "event": "Catalogue registration", "from": null, "to": "IN_BACKLOG", "at": "2026-09-02T10:40:43.220Z", "actor": "Linas", "authority": "Human project team member", "reason": "The Feature catalogue was accepted for governed documentation and retained in the backlog.", "conditions": [ "Registration records the accepted documentation boundary only.", "No solution or implementation approval is granted." ], "evidence_url": "https://discord.com/channels/1518726359512387766/1543925247361814568/1544658325738885201" } }