From b7ecd27076bb064e29756d34a4eb07da9bb8b8b6 Mon Sep 17 00:00:00 2001 From: hoelee Date: Tue, 29 Sep 2026 05:54:35 +0800 Subject: [PATCH] docs(project-state): correct the SSO rollback note (gate container is stopped, not running) --- docs/project-state.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/project-state.md b/docs/project-state.md index bd3ee73..88b7ae6 100644 --- a/docs/project-state.md +++ b/docs/project-state.md @@ -95,7 +95,7 @@ The user asked for the dashboard to be reachable remotely **without** publishing | Verified from the public internet (2026-09-29) | anonymous `/` → 302 → `/outpost.goauthentik.io/start` → `auth.hoelee.com/if/flow/auth-stats/…` → **200** (same shape as the working `auth-mysql` chain); `/login`, `/api/websites` → 302 gated; `/script.js` **200**, `/api/heartbeat` **200**, `POST /api/send` **400 app-level** | | End-to-end tracker through the SSO path | temp website + 2 pageviews POSTed to `https://stats.hoelee.com/api/send` → recorded **2 pageviews / 1 visitor / 1 session**, `country=MY, region=MY-07, city=George Town`, referrer metric `google.com` → **the outpost does not break `X-Forwarded-For`, geo still works**; temp website deleted | | Known trade-off (honest) | (1) SSO protects the *dashboard route*, but Umami has **no OIDC**, so after SSO the user still sees **Umami's own login page** — double login, expected, one-click after the first time (2FA is available per-account in Settings → Profile; `TWO_FACTOR_ENCRYPTION_KEY` already in the stack env). (2) `` remains a **LAN break-glass path that bypasses SSO** (still needs Umami credentials; verified closed from the internet) — delete/close it if that is not wanted. (3) If the authentik outpost goes down, the dashboard goes down with it (tracker too — but the site keeps loading, the tracker fails silently) | -| Rollback | Re-point the vhost + `ReverseProxy.json` back to `5410` (stack 285 is still running) and reload nginx → instantly back to the plain allowlist gate. Backups of both files sit next to the originals | +| Rollback | Start the gate again (`sudo /usr/local/bin/docker start umami-gateway`, or start stack 285 in Portainer) → re-point the vhost + `ReverseProxy.json` to `5410` → reload nginx. Backups of both files sit next to the originals. (The gate container is now **`Exited (0)`** — it was stopped once the outpost took over, so port 5410 is free; the stack is kept as the rollback asset) | | Note | The `hermes3` authentik API token expired mid-session (DB says `expires 2026-09-28 22:17:08Z`); the leftover self-test account was removed through authentik's own ORM (`ak shell`), so no admin-group test user is left behind | **Step E2 — Wire the two sites together (www.hoelee.com → blog).** ⏸ Deferred by user 2026-09-29