44 lines
2.6 KiB
Markdown
44 lines
2.6 KiB
Markdown
|
|
# HUB-WP-0012 browser source evidence — 2026-09-28
|
|||
|
|
|
|||
|
|
This is local implementation evidence, not live identity, entitlement, policy,
|
|||
|
|
archive-custody or deployment acceptance.
|
|||
|
|
|
|||
|
|
Implemented explicit browser composition with confidential OIDC code exchange,
|
|||
|
|
S256 PKCE, one-time browser-bound state, signed ID-token validation, nonce,
|
|||
|
|
authentication freshness, optional access-token hash binding and live root
|
|||
|
|
access authorization before session creation. Secure host-only cookies contain
|
|||
|
|
opaque IDs; tokens remain in bounded process-local memory. Sessions last no
|
|||
|
|
longer than five minutes or either token, and restart invalidates them.
|
|||
|
|
Cookie writes require exact Origin and CSRF; every protected request still
|
|||
|
|
rechecks identity/facts/policy/audit. Session validity is rechecked after authority
|
|||
|
|
awaits. Local logout remains available during owner outages. Browser refusal
|
|||
|
|
records exclude authorization codes, tokens and query parameters.
|
|||
|
|
|
|||
|
|
Two additional regressions are fixed: explicit controllers cannot silently run
|
|||
|
|
without enforcement, and slow request bodies time out before authority/handlers.
|
|||
|
|
|
|||
|
|
Validation:
|
|||
|
|
|
|||
|
|
- `HUB_CORE_AUDIT_CORE_SOURCE=/home/worsch/audit-core .venv/bin/python -m pytest -q --disable-warnings`:
|
|||
|
|
**328 passed**, one existing Starlette/httpx deprecation warning.
|
|||
|
|
- After the final correlation-ID adjustment, the browser suite passed again:
|
|||
|
|
**22 passed**. It uses actual RSA signatures, mock OIDC discovery/code exchange
|
|||
|
|
and synthetic authority/policy/audit owners. It covers replay/browser binding,
|
|||
|
|
bad nonce/audience/subject/authorized party/type/time/hash, non-root/non-platform/
|
|||
|
|
non-MFA denial, expiry/restart, grant withdrawal, CSRF and mixed credentials,
|
|||
|
|
logout during authority awaits, capacity and owner outage denial. A real native
|
|||
|
|
message handler accepts a valid session write and refuses a spoofed sender.
|
|||
|
|
- Wheel/source distribution build passes; the browser module is packaged.
|
|||
|
|
- Inventory drift/coverage check passes: **165 Hub source surfaces**, 48 platform
|
|||
|
|
rows and 250 dated cluster objects. Four optional browser protocol routes have
|
|||
|
|
their own profile; inventory coverage is not live conformance.
|
|||
|
|
- `git diff --check` passes.
|
|||
|
|
|
|||
|
|
Remaining gates: confidential issuer registration and real MFA behavior, immutable
|
|||
|
|
root and authoritative owner-facts integration, Hub policy admission including
|
|||
|
|
`hub.browser.session`, durable production audit delivery, proxy logging/rate limits,
|
|||
|
|
consumer adoption and complete platform acceptance. The source candidate provides
|
|||
|
|
neither distributed sessions, upstream IdP logout, automatic renewal nor operation
|
|||
|
|
completion auditing. T01–T04 remain in progress. No public listener or production
|
|||
|
|
entitlement changed.
|