Change Log
Version 4 · Record completed corrected Odin collection, confirmed database baseline, remaining first-cutover prerequisites and passing handoff CI.
Historical versionQDG Identity change log
Document version: 1.0.3. Updated 6 September 2026.
Corrected Odin evidence received
The collector 1.0.1 handoff completed on Odin and returned its sanitised report automatically. Local validation confirmed the expected report identity and collector source hash. The report resolves the previous service-configuration, package and database evidence gaps; another collection is not needed just to repeat these findings.
The existing KB service, private Python runtime and restricted database writer are working. Installed metadata reports the legacy KB release; the new Identity package, OAuth audit table/INSERT grant, protected user policy and discovery route still need provisioning. The first deployment needs an explicit, tested prerequisite phase before the existing cutover controller can proceed. Keep the original evidence intact and record the exact authorised additions separately.
Identity handoff CI passed on Windows and Ubuntu at 47d55f1, including 52 handoff checks on Windows. KB collector CI passed at c38e8ca. No production service settings or application artifacts changed.
First Odin evidence and collector correction
Received Robert's first sanitised Odin report and independently matched its supplied SHA-256. It confirms the existing service, dedicated account, private Python runtime and loopback listener. The report also identifies missing OAuth policy/discovery configuration and open ingress/logging review gates. No production OAuth change was made.
Collector 1.0.0 failed to recognize ordinary WinSW XML because a child field shadowed a PowerShell XML property. The original non-secret deployment template exactly reproduces the live file hash, allowing a regression without retrieving raw configuration. Collector 1.0.1 fixes that parser issue, recognizes lowercase package metadata names and validates report paths before collecting. The subsequent corrected live report resolved the package and database evidence gaps.
Added Robert's requested single-command handoff: transfer a reviewed ZIP through the existing RDP drive, verify its pinned hash, remove only matching old handoff artifacts, extract, run with a fresh full report path and return the report automatically. Existing reports and unrelated scripts are preserved. Source is in Identity's tools/Invoke-OdinCollectorHandoff.ps1.
Verification: 75 focused collector checks, 108 independent release-safety checks and 52 synthetic handoff checks passed locally. The handoff checks cover malicious/altered archives, path confinement, junctions, changed files, repeat runs, report preservation and strict report identity. Actual old-to-new archive installation and repeat refresh passed locally. GitHub also runs the handoff checks on Windows. The live collector completion is recorded separately above.
Collector source: KB commit c38e8cabcd069fd59074fcb2dc337ea3c12351f2. Shared Identity 0.2.0 and KB application 1.2.0 wheel bytes are unchanged.
Identity 0.2.0 and KB MCP 1.2.0 preparation
Added the shared Auth0 token verifier, current subject permissions, stable request identity, exact MCP discovery and a bounded local synthetic pilot. The KB integration preserves all ten tools, adds current tool-level permission checks and commits identity audit with each permitted content write.
Added explicitly activated emergency reads for one approved Robert identity, with an absolute maximum one-hour lifetime, current policy enforcement and durable audit before data release. It is disabled by default and permits no writes or automatic fallback. Added private credential preparation that never activates service access or prints a token.
Added the read-only Odin collector, the reviewed deployment controller and its semantic probes. The workflow binds exact host/configuration/artifact hashes, detects drift, stages offline, protects backups, stops only KB MCP and requires verified canaries. Recovery preserves current denials and refuses an automatic return to retired static authentication.
Confirmed day-one scope: QDG Knowledge Base MCP only, with new OAuth credentials independent of existing QDBAuth credentials. Other services and websites retain their current authentication until individually migrated after the first service is verified.
Adopted the non-conflicting Start_Project standards: confirmed Python plus PowerShell, QDG Identity as the Knowledge Base project, the four standard pages, a consolidated changelog/handover, script versions and the existing Git/immutable-release archive approach.
Published all four standard pages with content readback verification. These explain OAuth usage, architecture and reasoning, deployment, outage behaviour and remaining live gates. A BA review clarified independent read/write permissions, service-specific access removal and the distinction between pilot and production resources, and added links to current operating guides. Robert requested a detailed additional-service integration guide after the working implementation is verified; How to Use now records its required evidence, tested example, independent walkthrough and Robert's acceptance. That guide remains pending rather than presenting assumptions as tested instructions.
Verification evidence
- 392 local Identity/joint-pilot tests passed. Two symbolic-link cases require Linux CI because local Windows did not permit link creation.
- 102 local KB tests passed using the actual hash-locked Identity wheel, including five isolated real MySQL tests for audit, grants, rollback and the read-only deployment probe.
- 46 focused collector checks, 25 deployment/SCM fixtures and 108 independent release-safety cases passed. Existing OAuth preparation and upgrade failure regressions also passed.
- A fresh offline installation of all 32 production runtime packages passed dependency checks, exact distribution comparison and isolated installed-package imports.
- Hosted Windows fixture failures were reproduced and corrected without weakening production checks: shortened temporary paths required canonical fixture directories, and PowerShell 5.1 closures needed an explicitly captured assertion function when called from another script. All five PowerShell suites then passed together in the hosted runner.
- Identity Windows/Linux CI passed at
2a34c44; KB Windows CI passed atbdf488d. Check the exact current PR head again if later changes are added.
Identity implementation source: b2c5e791a01c5e2e04265ba6c2db63dc22fab856; standards and collector handoff package: 2a34c44dae3b2ba1cc9ded7e179fef32c10f9ea7. KB application source: 8671df3d30c3782c6d142ba6cbfa295451c2a7ed; release metadata and CI fixture follow-ups: b108c9730de0ed36732ddf4de0de557ef906b8a1 and bdf488d9179a80bcb4a6127840b67d1c13db45e0. These documentation/test corrections do not replace the immutable built application wheels.
Identity PR #1 and KB MCP PR #2 contain the reviewed work. These are open delivery changes, not a record of production activation.
Outstanding acceptance
Complete the actual Auth0 end-user login and Codex desktop read/write, renewal, restart and revocation proof. Use the reviewed Odin report to resolve the runtime/policy/database/ingress/ACL prerequisites and prepare the final host-specific execution package. Rehearse production and emergency recovery before cutover.
No production deployment, token retirement for the live MCP, other-service migration or emergency activation is recorded by this delivery. No OneDrive sync was performed.