docs: integrate second autonomous migration wave

This commit is contained in:
Jason Woltje
2026-08-10 18:33:02 -05:00
parent 6b3ebce343
commit 16920c4a6f
8 changed files with 75 additions and 35 deletions
+4 -3
View File
@@ -1,16 +1,17 @@
# Security
> **Status:** Initial migration active. The SSO provider runbook is current; other security pages remain planned.
> **Status:** Partially migrated. The SSO provider and Discord ingress security pages are current.
This chapter will contain authentication, authorization, SSO, secrets, RBAC, and security-control guidance for administrators.
## Planned pages
- [`sso-providers.md`](sso-providers.md) — current provider configuration, discovery, callbacks, and failure modes.
- `secrets.md` — document secret handling after source/configuration verification.
- [`discord-ingress.md`](discord-ingress.md) — current Discord service authentication, allowlists, bindings, roles, replay, and failure controls.
- `secrets.md` — document general secret handling after source/configuration verification.
- `rbac.md` — document roles and permissions from the canonical implementation.
The current SSO page reflects the dynamic provider-discovery behavior. Do not revive the retired root document or add frontend feature flags that the web flow does not consume.
The current SSO page reflects dynamic provider discovery. The Discord page documents only the verified Discord compatibility boundary; it does not claim Telegram or Matrix parity. Do not revive retired root documents or add frontend feature flags that the web flow does not consume.
## Related