Implement NetKingdom identity shell for coulomb.social (CSOC-WP-0002)

Django scaffold aligned with the business delivery lane: tenant-keyed
Member model without passwords, identity app as sole OIDC/session
boundary, dev-claims login, authenticated /app/ shell, ADR-0001, and
tests. T01/T02/T05/T06 done; OIDC registration, real user-engine HTTP,
flex-auth, and packaging remain open.
This commit is contained in:
tegwick 2026-08-09 01:45:05 +02:00
parent 2ec7761504
commit 01da195c13
51 changed files with 2215 additions and 41 deletions

View file

@ -0,0 +1,90 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{% block title %}{{ site_name }}{% endblock %}</title>
<style>
:root {
--color-primary: #d08728;
--color-bg: #ffffff;
--color-text: #171717;
--color-muted: #616161;
--radius: 8px;
}
* { box-sizing: border-box; }
body {
margin: 0;
font-family: Inter, Helvetica, system-ui, sans-serif;
background: var(--color-bg);
color: var(--color-text);
line-height: 1.5;
}
header {
display: flex;
justify-content: space-between;
align-items: center;
padding: 1rem 1.5rem;
border-bottom: 1px solid #e5e5e5;
}
header a { color: inherit; text-decoration: none; font-weight: 600; }
main { max-width: 48rem; margin: 0 auto; padding: 2.5rem 1.5rem; }
.btn {
display: inline-block;
padding: 0.75rem 1.25rem;
background: var(--color-primary);
color: #fff;
border-radius: var(--radius);
text-decoration: none;
border: none;
font: inherit;
font-weight: 600;
cursor: pointer;
}
.btn.secondary { background: #171717; }
.muted { color: var(--color-muted); }
.card {
border: 1px solid #e5e5e5;
border-radius: var(--radius);
padding: 1.25rem;
margin-top: 1.5rem;
}
.messages { list-style: none; padding: 0; }
.messages li { padding: 0.5rem 0; color: #b45309; }
label { display: block; margin-top: 0.75rem; font-size: 0.9rem; }
input[type=text], input[type=email] {
width: 100%;
padding: 0.5rem 0.75rem;
margin-top: 0.25rem;
border: 1px solid #ccc;
border-radius: 6px;
}
dl { display: grid; grid-template-columns: 10rem 1fr; gap: 0.35rem 1rem; }
dt { color: var(--color-muted); }
dd { margin: 0; word-break: break-all; }
</style>
{% block extra_head %}{% endblock %}
</head>
<body>
<header>
<a href="{% url 'core:landing' %}">{{ site_name }}</a>
<nav>
{% if user.is_authenticated %}
<a class="btn secondary" href="{% url 'identity:logout' %}">Sign out</a>
{% else %}
<a class="btn" href="{% url 'identity:login' %}">Sign in</a>
{% endif %}
</nav>
</header>
<main>
{% if messages %}
<ul class="messages">
{% for message in messages %}
<li>{{ message }}</li>
{% endfor %}
</ul>
{% endif %}
{% block content %}{% endblock %}
</main>
</body>
</html>

View file

@ -0,0 +1,17 @@
{% extends "base.html" %}
{% block title %}Home — {{ site_name }}{% endblock %}
{% block content %}
<h1>Signed in</h1>
<p class="muted">Authenticated shell (CSOC-WP-0002). Content surfaces come later.</p>
<div class="card">
<h2 style="margin-top:0;">Principal</h2>
<dl>
<dt>Display name</dt><dd>{{ principal.display_name }}</dd>
<dt>Username</dt><dd>{{ principal.username }}</dd>
<dt>Tenant</dt><dd>{{ principal.tenant_id }}</dd>
<dt>Issuer</dt><dd>{{ principal.issuer }}</dd>
<dt>Subject</dt><dd>{{ principal.subject }}</dd>
<dt>user-engine id</dt><dd>{{ principal.user_engine_user_id }}</dd>
</dl>
</div>
{% endblock %}

View file

@ -0,0 +1,16 @@
{% extends "base.html" %}
{% block title %}{{ site_name }} — co-creation{% endblock %}
{% block content %}
<h1>coulomb.social</h1>
<p class="muted">
Co-creation platform reestablished on the Railiance / NetKingdom stack.
Members sign in through platform identity — not Bubble.
</p>
<p>
<a class="btn" href="{% url 'identity:login' %}">Sign in</a>
</p>
<p class="muted" style="margin-top: 2rem; font-size: 0.85rem;">
Tenant: {{ default_tenant_id }} · OIDC:
{% if oidc_enabled %}enabled{% else %}dev / not configured{% endif %}
</p>
{% endblock %}

View file

@ -0,0 +1,30 @@
{% extends "base.html" %}
{% block title %}Dev sign-in — {{ site_name }}{% endblock %}
{% block content %}
<h1>Dev sign-in</h1>
<p class="muted">
DEBUG only. Simulates NetKingdom IAM Profile claims when
<code>OIDC_ENABLED=false</code>. Not available in production.
</p>
<form method="post" class="card">
{% csrf_token %}
<label>Subject (OIDC sub) *
<input type="text" name="subject" required placeholder="user-123" value="dev-user-1">
</label>
<label>Issuer
<input type="text" name="issuer" value="https://local.dev/issuer">
</label>
<label>Name
<input type="text" name="name" value="Dev Member">
</label>
<label>Email
<input type="email" name="email" value="dev@example.com">
</label>
<label>Preferred username
<input type="text" name="preferred_username" value="dev">
</label>
<p style="margin-top:1.25rem;">
<button class="btn" type="submit">Establish session</button>
</p>
</form>
{% endblock %}