feat: add OIDC browser sessions with live access enforcement
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
fdea2f5192
commit
a15fe032b0
14 changed files with 807 additions and 31 deletions
43
docs/evidence/hub-wp-0012-browser-20260928.md
Normal file
43
docs/evidence/hub-wp-0012-browser-20260928.md
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
# HUB-WP-0012 browser source evidence — 2026-09-28
|
||||
|
||||
This is local implementation evidence, not live identity, entitlement, policy,
|
||||
archive-custody or deployment acceptance.
|
||||
|
||||
Implemented explicit browser composition with confidential OIDC code exchange,
|
||||
S256 PKCE, one-time browser-bound state, signed ID-token validation, nonce,
|
||||
authentication freshness, optional access-token hash binding and live root
|
||||
access authorization before session creation. Secure host-only cookies contain
|
||||
opaque IDs; tokens remain in bounded process-local memory. Sessions last no
|
||||
longer than five minutes or either token, and restart invalidates them.
|
||||
Cookie writes require exact Origin and CSRF; every protected request still
|
||||
rechecks identity/facts/policy/audit. Session validity is rechecked after authority
|
||||
awaits. Local logout remains available during owner outages. Browser refusal
|
||||
records exclude authorization codes, tokens and query parameters.
|
||||
|
||||
Two additional regressions are fixed: explicit controllers cannot silently run
|
||||
without enforcement, and slow request bodies time out before authority/handlers.
|
||||
|
||||
Validation:
|
||||
|
||||
- `HUB_CORE_AUDIT_CORE_SOURCE=/home/worsch/audit-core .venv/bin/python -m pytest -q --disable-warnings`:
|
||||
**328 passed**, one existing Starlette/httpx deprecation warning.
|
||||
- After the final correlation-ID adjustment, the browser suite passed again:
|
||||
**22 passed**. It uses actual RSA signatures, mock OIDC discovery/code exchange
|
||||
and synthetic authority/policy/audit owners. It covers replay/browser binding,
|
||||
bad nonce/audience/subject/authorized party/type/time/hash, non-root/non-platform/
|
||||
non-MFA denial, expiry/restart, grant withdrawal, CSRF and mixed credentials,
|
||||
logout during authority awaits, capacity and owner outage denial. A real native
|
||||
message handler accepts a valid session write and refuses a spoofed sender.
|
||||
- Wheel/source distribution build passes; the browser module is packaged.
|
||||
- Inventory drift/coverage check passes: **165 Hub source surfaces**, 48 platform
|
||||
rows and 250 dated cluster objects. Four optional browser protocol routes have
|
||||
their own profile; inventory coverage is not live conformance.
|
||||
- `git diff --check` passes.
|
||||
|
||||
Remaining gates: confidential issuer registration and real MFA behavior, immutable
|
||||
root and authoritative owner-facts integration, Hub policy admission including
|
||||
`hub.browser.session`, durable production audit delivery, proxy logging/rate limits,
|
||||
consumer adoption and complete platform acceptance. The source candidate provides
|
||||
neither distributed sessions, upstream IdP logout, automatic renewal nor operation
|
||||
completion auditing. T01–T04 remain in progress. No public listener or production
|
||||
entitlement changed.
|
||||
Loading…
Add table
Add a link
Reference in a new issue