NEXT-SESSION.md45 lines · main
1# Next session — pick up here
2
3**Saved:** 2026-07-27
4**Owner:** flndrn
5
6---
7
8## One-line status
9
10**Mavi pay login live:** magic link · email OTP · Konnos OAuth.
11**AUTH-HARDEN-90 test phase (T1–T8):** evidence filed 2026-07-29 — FDI lock, proxy, refresh contract, M2M fail path, IdP discovery, migration unit, captcha off.
12**Gold-path app fixes (local):** Mavi legacy proxy remap, Krypco session/me, Konnos JWKS, `@briven/auth` getSession → engine. **Ship Mavi** still needed.
13**Paused:** passkeys human retest · SMS/Twilio (or N/A).
14**Full detail:** [`AUTH-HARDEN-TEST-EVIDENCE-2026-07-29.md`](./AUTH-HARDEN-TEST-EVIDENCE-2026-07-29.md) · [`SESSION-RESUME-2026-07-27-AUTH.md`](./SESSION-RESUME-2026-07-27-AUTH.md)
15
16---
17
18## Read first
19
201. `docs/SESSION-RESUME-2026-07-27-AUTH.md`
212. `docs/AUTH-SUPERTOKENS-PARITY-MATRIX.md` (if parity work)
223. `docs/knowledge-base.md` before any Auth code change
23
24---
25
26## Quick choices
27
28| If you want… | Do this |
29|--------------|---------|
30| Continue Auth tests | Resume passkeys **or** SMS from the session resume file |
31| Pando login | Pando session + `pando/docs/HANDOFF-BRIVEN-AUTH-FOR-PANDO.md` only |
32| Machine auth for any app | `docs/HANDOFF-AUTH-M2M-FOR-ALL-PROJECTS.md` |
33| Ship product on mavi | Auth is good enough without SMS/passkeys |
34
35---
36
37## Remotes / deploy notes
38
39- Briven laptop may be **ahead of origin**; France deploys often via rsync + `safe-redeploy-service.sh` when push 403s.
40- Mavi: Dokploy app `app-override-multi-byte-program-hsf4uj` on kvm4 (`187.124.209.17`).
41- Briven France: `187.124.64.116` compose `briven-brivenfrance-uilsk6`.
42
43---
44
45*Update this file when you close a major block.*
Preview

Next session — pick up here

Saved: 2026-07-27
Owner: flndrn


One-line status

Mavi pay login live: magic link · email OTP · Konnos OAuth.
AUTH-HARDEN-90 test phase (T1–T8): evidence filed 2026-07-29 — FDI lock, proxy, refresh contract, M2M fail path, IdP discovery, migration unit, captcha off.
Gold-path app fixes (local): Mavi legacy proxy remap, Krypco session/me, Konnos JWKS, @briven/auth getSession → engine. Ship Mavi still needed.
Paused: passkeys human retest · SMS/Twilio (or N/A).
Full detail: AUTH-HARDEN-TEST-EVIDENCE-2026-07-29.md · SESSION-RESUME-2026-07-27-AUTH.md


Read first

  1. docs/SESSION-RESUME-2026-07-27-AUTH.md
  2. docs/AUTH-SUPERTOKENS-PARITY-MATRIX.md (if parity work)
  3. docs/knowledge-base.md before any Auth code change

Quick choices

If you want…Do this
Continue Auth testsResume passkeys or SMS from the session resume file
Pando loginPando session + pando/docs/HANDOFF-BRIVEN-AUTH-FOR-PANDO.md only
Machine auth for any appdocs/HANDOFF-AUTH-M2M-FOR-ALL-PROJECTS.md
Ship product on maviAuth is good enough without SMS/passkeys

Remotes / deploy notes

  • Briven laptop may be ahead of origin; France deploys often via rsync + safe-redeploy-service.sh when push 403s.
  • Mavi: Dokploy app app-override-multi-byte-program-hsf4uj on kvm4 (187.124.209.17).
  • Briven France: 187.124.64.116 compose briven-brivenfrance-uilsk6.

Update this file when you close a major block.