QDG Knowledge Base Read-only viewer QWebHub
changelog

Change Log

Version 11 · Record verified deployment bundle, path/repeat-run tests and the Prepare/report workflow before Odin cutover.

Historical version

QDG Identity change log

Document version: 1.0.10. Updated 6 September 2026.

Complete deployment bundle and reviewed operator handoff

Built the version 1.0.0 RDP fetch/check/run/report workflow and immutable Git-archive bundle for KB 1.2.0, Identity 0.2.0 and all 32 pinned runtime wheels. The next operator invocation runs Prepare: fresh drift and missing host observations, private configuration candidates, offline installation rehearsal and automatic sanitized report return. No Odin cutover has been performed; the running service, other QDG services and their credentials are unchanged.

Two independent reviews supplied 208 passing Windows PowerShell 5.1 safety cases for the new handoff and worker, including slash conversion, spaces, underscores, rejected short aliases, archive integrity, bounded cleanup, preserved reports and explicit controller dispatch. The 402-test local Identity/pilot suite and Ruff passed. Actual ZIP extraction and repeated installation passed in a space/underscore path; all nine included PowerShell scripts parsed. A fresh offline installation from that exact ZIP passed 32-package inventory, isolated installed-server import and dependency consistency through the actual packaged process helper.

Preflight and Deploy retain the existing exact-plan controller, private DBA prompt and genuine host/client acceptance gates. Fixed failure-stage codes help diagnose returned checks without publishing secrets or raw diagnostics. Local synthetic tests and offline installation do not prove actual Odin Administrator ACLs or production authentication.

Approved production Auth0 registration

Applied Robert's approved production KB registration contract in the existing AU tenant. Created the separate API and strict native Codex client, configured the exact callback and explicit read/write grant, and verified ten-minute access-token lifetimes and rotating refresh with a 24-hour maximum, one-hour idle limit and zero overlap. API offline access was enabled only after the saved client limits were checked.

Reloaded the settings and permission grants. Only the new production client has the two production KB permissions; machine access is denied, and the new client has no pilot or Management API permissions. Auth0 also created its standard unused test application; it has no API access. The existing dedicated directory, disabled public signup, enabled resource compatibility and disabled DCR/CIMD were rechecked without changing them.

The sanitized saved API observation matches the desired candidate with no differences. Independent JSON/TOML validation passed for the proposed settings and disabled additive Codex snippet. The private production entitlement validates with one enabled owner identity; preparation verified private access rules and preserved the exact active pilot policy. Personal mappings and credentials were not published.

Documented the distinction between Auth0's native public-client default and direct field evidence. Actual production S256/secretless login, Odin deployment, authentication/retention, ingress, durable audit and recovery remain separate acceptance checks. Runtime artifacts and current services are unchanged; no tokens were retired, no subscription was purchased and no other service was migrated.

Free-first budget and account review

Recorded Robert's decision to launch on Free and use Essentials when an actual need justifies an upgrade. Verified the signed-in Free subscription and the small-user monthly quote, distinguishing it from temporary trial entitlements. No purchase or access-setting change was made.

An independent primary-source review supports the core strict MCP OAuth features beyond the trial. Production preparation now accounts for the single-tenant allowance and preserves the outstanding MFA, retention and environment decisions. Application hostnames and branded Auth0 login domains are separate requirements; the intended upgrade tier is not assumed sufficient for every future integration. The new plan-readiness record preserves sources and evidence limits. Existing runtime packages and Odin services remain unchanged.

Direct desktop-attached pilot proof

Following Robert's restart, a fresh desktop-managed agent directly exercised all ten attached pilot tools. Guarded synthetic project/page creation, Markdown validation, exact version-1 and version-2 readback, update, stale conflict without overwrite, immutable history and search all passed. The existing pilot fixture was preserved. This run used the attached OAuth pilot connection, with no independent CLI harness or production KB connector supplying the proof.

The app had updated its bundled CLI to 0.153.4. Its stopped synthetic service was restarted, and fresh authorization succeeded after a saved refresh token received a generic rejection. The precise reason for that rejection is unconfirmed. The older task retains an earlier connection failure, while the fresh desktop connection works. No approval request or decision was observable; approval UI, the separate desktop build and full restart/recovery behavior remain open. C2's functional tool checks pass; C2/C3 are not fully closed.

The executive summary and rollout records now distinguish automated source tests, independent engine proof, direct desktop-attached proof and production acceptance. The next release preparation uses the accepted Odin report for production identity settings, exact candidate artifacts/configuration, initial audit/policy provisioning, ingress/logging/permission evidence and recovery. No new production access, runtime artifact change, token retirement or other-service migration occurred.

Actual Auth0 login and Codex engine proof

Robert completed hosted sign-in and consent, and the installed Codex client confirmed a successful OAuth exchange. Independent Codex app-server processes used the saved login to discover and exercise all ten KB tools against the synthetic local backend. Test writes, exact readback, history/search, stable server-owned attribution and stale-version conflict protection passed. The harness did not read or copy OAuth tokens, start a model turn, or create a stored task.

Using the existing login, current read-only policy allowed reads and rejected writes with HTTP 403. Disabling the approved identity rejected reads with HTTP 403. The exact original policy was restored, access returned, and the denied write had not altered content. Independent review confirmed the ephemeral test method and its limits. These checks establish current service-policy enforcement; read-only-token scope upgrade and organisation-wide account revocation are separate tests.

Timed renewal passed: a fresh Codex process completed all ten tools without another browser authorization after the original token could no longer be accepted, including all permitted clock allowance. Refresh replay detection and idle/maximum-limit enforcement were not independently exercised. Desktop observations were still open at this engine-proof milestone; subsequent attached-client results are recorded above. Engine proof remains separate from desktop observations and Odin/real-database acceptance. No production change or other-service migration was made.

Development login directory and verified pilot account

Created Robert's approved dedicated QDG-Identity-Pilot-Users database connection in the existing Development tenant. Public signup is disabled; domain-level login is enabled. The existing login directory was preserved. Domain-level availability applies to third-party clients in this tenant, while explicit API/client grants and the MCP user policy remain the separate access controls. No subscription purchase was made; production subscription readiness remains open.

Robert created his application account, chose its new password directly and completed email verification. The refreshed administrative profile confirmed the correct connection and verified email. Only his approved identity was added to protected local pilot policy; personal identifiers and credentials are excluded from shared documentation.

Added a separate Codex pilot entry while preserving existing configuration. The installed synthetic pilot serves public resource metadata and rejects unauthenticated MCP requests. The actual CLI authorization request reaches the correct hosted login and uses PKCE S256, the exact callback, one local resource and read/write/offline scopes. One listener expired without receiving a callback, so it requires a fresh request. No completed OAuth exchange, desktop tool-use or token-renewal proof is claimed yet.

An independent review confirmed the access-token verifier and deliberate read-first discovery contract do not require changes for this connection setup. Existing runtime artifacts and Odin services remain unchanged. The next functional checkpoint is Robert's successful hosted sign-in followed by actual desktop read/write, renewal and removal tests.

Initial OAuth cutover automation

Added deployment controller 1.1.0's explicit first-cutover mode. It preserves the original readiness report, verifies the actual database state, creates only the reviewed audit table and INSERT permission, and publishes the approved initial user policy without overwriting an existing file. It records and verifies each transition before stopping KB MCP. Normal upgrade checks remain in place.

Added secure local database-administrator input with private permissions from file creation, references-only output and cleanup restricted to the unchanged generated input. The password stays on Odin and outside chat, process arguments and the transferable package. Existing operator credential files are preserved. The deployment does not create database administrators, change runtime passwords or migrate other services.

Probe 1.0.1 now checks the database before measuring token validity, requiring five minutes remaining before the service switch. Independent review corrected receipt numeric-type handling, changed parent permissions, post-publication file aliases and metadata-visibility checks. A real temporary MySQL instance exercised the exact audit creation and restricted grant; it exposed collation-dependent index ordering, which was corrected without relaxing the schema requirements.

Final combined verification passed 197 Python tests, including ten isolated real-MySQL cases on temporary MySQL 8.4.9. All eight Windows PowerShell 5.1 suites passed together, including 36 first-cutover cases, 69 independent safety cases and 16 secure administrator-input cases. Ruff and installed dependency checks passed. Odin's MySQL 8.4.7 has not run the deployment.

Implementation source: KB commit bb596b4. Its Windows CI run passed, including all eight PowerShell suites. Hosted CI explicitly skips the ten opt-in real-engine cases, which passed locally. Production ingress evidence, Robert's actual Auth0/Codex proof and the final reviewed Odin execution remain outstanding. Existing application wheels and released collector packages remain unchanged.

Corrected Odin evidence received

The collector 1.0.1 handoff completed on Odin and returned its sanitised report automatically. Local validation confirmed the expected report identity and collector source hash. The report resolves the previous service-configuration, package and database evidence gaps; another collection is not needed just to repeat these findings.

The existing KB service, private Python runtime and restricted database writer are working. Installed metadata reports the legacy KB release; the new Identity package, OAuth audit table/INSERT grant, protected user policy and discovery route still need provisioning. The first deployment needs an explicit, tested prerequisite phase before the existing cutover controller can proceed. Keep the original evidence intact and record the exact authorised additions separately.

Identity handoff CI passed on Windows and Ubuntu at 47d55f1, including 52 handoff checks on Windows. KB collector CI passed at c38e8ca. No production service settings or application artifacts changed.

First Odin evidence and collector correction

Received Robert's first sanitised Odin report and independently matched its supplied SHA-256. It confirms the existing service, dedicated account, private Python runtime and loopback listener. The report also identifies missing OAuth policy/discovery configuration and open ingress/logging review gates. No production OAuth change was made.

Collector 1.0.0 failed to recognize ordinary WinSW XML because a child field shadowed a PowerShell XML property. The original non-secret deployment template exactly reproduces the live file hash, allowing a regression without retrieving raw configuration. Collector 1.0.1 fixes that parser issue, recognizes lowercase package metadata names and validates report paths before collecting. The subsequent corrected live report resolved the package and database evidence gaps.

Added Robert's requested single-command handoff: transfer a reviewed ZIP through the existing RDP drive, verify its pinned hash, remove only matching old handoff artifacts, extract, run with a fresh full report path and return the report automatically. Existing reports and unrelated scripts are preserved. Source is in Identity's tools/Invoke-OdinCollectorHandoff.ps1.

Verification: 75 focused collector checks, 108 independent release-safety checks and 52 synthetic handoff checks passed locally. The handoff checks cover malicious/altered archives, path confinement, junctions, changed files, repeat runs, report preservation and strict report identity. Actual old-to-new archive installation and repeat refresh passed locally. GitHub also runs the handoff checks on Windows. The live collector completion is recorded separately above.

Collector source: KB commit c38e8cabcd069fd59074fcb2dc337ea3c12351f2. Shared Identity 0.2.0 and KB application 1.2.0 wheel bytes are unchanged.

Identity 0.2.0 and KB MCP 1.2.0 preparation

Added the shared Auth0 token verifier, current subject permissions, stable request identity, exact MCP discovery and a bounded local synthetic pilot. The KB integration preserves all ten tools, adds current tool-level permission checks and commits identity audit with each permitted content write.

Added explicitly activated emergency reads for one approved Robert identity, with an absolute maximum one-hour lifetime, current policy enforcement and durable audit before data release. It is disabled by default and permits no writes or automatic fallback. Added private credential preparation that never activates service access or prints a token.

Added the read-only Odin collector, the reviewed deployment controller and its semantic probes. The workflow binds exact host/configuration/artifact hashes, detects drift, stages offline, protects backups, stops only KB MCP and requires verified canaries. Recovery preserves current denials and refuses an automatic return to retired static authentication.

Confirmed day-one scope: QDG Knowledge Base MCP only, with new OAuth credentials independent of existing QDBAuth credentials. Other services and websites retain their current authentication until individually migrated after the first service is verified.

Adopted the non-conflicting Start_Project standards: confirmed Python plus PowerShell, QDG Identity as the Knowledge Base project, the four standard pages, a consolidated changelog/handover, script versions and the existing Git/immutable-release archive approach.

Published all four standard pages with content readback verification. These explain OAuth usage, architecture and reasoning, deployment, outage behaviour and remaining live gates. A BA review clarified independent read/write permissions, service-specific access removal and the distinction between pilot and production resources, and added links to current operating guides. Robert requested a detailed additional-service integration guide after the working implementation is verified; How to Use now records its required evidence, tested example, independent walkthrough and Robert's acceptance. That guide remains pending rather than presenting assumptions as tested instructions.

Verification evidence

  • 392 local Identity/joint-pilot tests passed. Two symbolic-link cases require Linux CI because local Windows did not permit link creation.
  • 102 local KB tests passed using the actual hash-locked Identity wheel, including five isolated real MySQL tests for audit, grants, rollback and the read-only deployment probe.
  • 46 focused collector checks, 25 deployment/SCM fixtures and 108 independent release-safety cases passed. Existing OAuth preparation and upgrade failure regressions also passed.
  • A fresh offline installation of all 32 production runtime packages passed dependency checks, exact distribution comparison and isolated installed-package imports.
  • Hosted Windows fixture failures were reproduced and corrected without weakening production checks: shortened temporary paths required canonical fixture directories, and PowerShell 5.1 closures needed an explicitly captured assertion function when called from another script. All five PowerShell suites then passed together in the hosted runner.
  • Identity Windows/Linux CI passed at 2a34c44; KB Windows CI passed at bdf488d. Check the exact current PR head again if later changes are added.

Identity implementation source: b2c5e791a01c5e2e04265ba6c2db63dc22fab856; standards and collector handoff package: 2a34c44dae3b2ba1cc9ded7e179fef32c10f9ea7. KB application source: 8671df3d30c3782c6d142ba6cbfa295451c2a7ed; release metadata and CI fixture follow-ups: b108c9730de0ed36732ddf4de0de557ef906b8a1 and bdf488d9179a80bcb4a6127840b67d1c13db45e0. These documentation/test corrections do not replace the immutable built application wheels.

Identity PR #1 and KB MCP PR #2 contain the reviewed work. These are open delivery changes, not a record of production activation.

Outstanding acceptance

The actual hosted login, Codex engine read/write/conflict, current-policy removal/restoration and continued use beyond initial token expiry are proven. Direct desktop-attached read/write/history/conflict also passes. Complete the remaining approval and retained-task recovery/restart observations. Use the reviewed Odin report to resolve the runtime/policy/database/ingress/ACL prerequisites and prepare the final host-specific execution package. Rehearse production and emergency recovery before cutover.

No production deployment, token retirement for the live MCP, other-service migration or emergency activation is recorded by this delivery. No OneDrive sync was performed.

Updated by Robert on Sept. 6, 2026, 1:37 p.m. · Commit: 44b7777dc40967cc726c971ceacb9ed0c4173768