summaryrefslogtreecommitdiff
path: root/docs/domain-authorization-user.md
diff options
context:
space:
mode:
authorSomhairle H. Marisol <[email protected]>2026-09-18 08:27:41 +0800
committerSomhairle H. Marisol <[email protected]>2026-09-18 08:27:41 +0800
commit088735b948d46896b8af30efcb0a2dc5d362b97f (patch)
tree0dcab0d5ebc65309267a42d7cda827e9fdd866e7 /docs/domain-authorization-user.md
parentbf6681eb29ac8b0c80ca17b2b5869f7de3da1198 (diff)
downloadstrategy-lab-088735b948d46896b8af30efcb0a2dc5d362b97f.tar.gz
docs(release): 全周期交接文档入库(含 ui-shadcn 迁移交付说明)
[变更性质] 纯文档提交,无运行时逻辑。 [文档内容] 补齐此前各轮未入库的交接/验收文档:backend-auth/backend-domain/ domain-authorization-user(认证与授权域)、etf-recovery-release- handoff(ETF 修复 + ops 演练定稿与生产部署命令)、recovery-* 系列、 frontend/parent-ui-findings(UI 迁移上下文)、worker/integration 等, 以及本轮 docs/ui-shadcn-handoff.md(shadcn-svelte 迁移交接,含 Chart.svelte 契约、runes $state 踩坑记录与 375/768/1440 验证证据)。 [更新方案] 按主题分文;每份文档只记录可复现的命令、验证结果与语义边界, 不导出密钥或生产敏感路径。 [影响范围] 文档渠道:后续 leader/client 审阅入口;与代码提交一一对应便于回溯。
Diffstat (limited to 'docs/domain-authorization-user.md')
-rw-r--r--docs/domain-authorization-user.md8
1 files changed, 8 insertions, 0 deletions
diff --git a/docs/domain-authorization-user.md b/docs/domain-authorization-user.md
new file mode 100644
index 0000000..2db054a
--- /dev/null
+++ b/docs/domain-authorization-user.md
@@ -0,0 +1,8 @@
+# Explicit user authorization — supersedes earlier domain ambiguity
+
+Latest direct user message in the current Matrix thread:
+> 好, 你可以部署到 fin.somhairle.bid 上
+
+The user explicitly authorizes public deployment to https://fin.somhairle.bid. Earlier .bin/.bid ambiguity and any instruction to report a domain-decision blocker are resolved and superseded. Continue deployment to exactly fin.somhairle.bid, preserving existing Cloudflare ingress and --protocol http2. Do not ask the domain question again.
+
+Current verified production candidate is strategy-lab-production.service at 127.0.0.1:8789; read docs/production-local.md and actual service/config before changing anything. Verify production asset freshness, origin/secure-cookie settings for HTTPS, authentication and permission gates before exposure. Append only the new ingress before the existing404 fallback, route DNS for the existing tunnel, validate and read back exact config, restart only cloudflared as needed, preserve other services and verify their routes. Independently verify the actual public endpoint, login and static assets. Complete remaining acceptance and then deliver completion once via established notification mechanism.