feat: add OIDC browser sessions with live access enforcement
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
fdea2f5192
commit
a15fe032b0
14 changed files with 807 additions and 31 deletions
|
|
@ -118,6 +118,23 @@
|
|||
"audience": "none: minimal process liveness",
|
||||
"test_owner": "hub-core",
|
||||
"enforcement": "No identity required; no sensitive details"
|
||||
},
|
||||
"browser-session": {
|
||||
"actor_tenant": "tenant:platform for root; named workload tenant otherwise",
|
||||
"target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited",
|
||||
"action_resource_rule": "hub.browser.session for login/session authority; protected API uses existing route action",
|
||||
"cases": [
|
||||
"ROOT",
|
||||
"OTHER",
|
||||
"INVALID",
|
||||
"REVOKE",
|
||||
"OUTAGE",
|
||||
"BYPASS",
|
||||
"CALLER"
|
||||
],
|
||||
"audience": "hub-browser (OIDC ID token); hub-core (access token); deployment registration required",
|
||||
"test_owner": "hub-core",
|
||||
"enforcement": "Explicit BrowserSessions: login is public initiation; callback requires one-time browser-bound state, PKCE and nonce; session requires current authority; logout requires session and CSRF"
|
||||
}
|
||||
},
|
||||
"acceptance_cases": {
|
||||
|
|
@ -399,6 +416,39 @@
|
|||
"conditional": false,
|
||||
"handler": "list_widgets"
|
||||
},
|
||||
{
|
||||
"id": "http:GET:/auth/callback:hub_core.security.browser.browser_flow",
|
||||
"kind": "runtime-http",
|
||||
"method": "GET",
|
||||
"path": "/auth/callback",
|
||||
"profile": "browser-session",
|
||||
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
|
||||
"source": "hub_core.security.browser",
|
||||
"conditional": true,
|
||||
"handler": "browser_flow"
|
||||
},
|
||||
{
|
||||
"id": "http:GET:/auth/login:hub_core.security.browser.browser_flow",
|
||||
"kind": "runtime-http",
|
||||
"method": "GET",
|
||||
"path": "/auth/login",
|
||||
"profile": "browser-session",
|
||||
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
|
||||
"source": "hub_core.security.browser",
|
||||
"conditional": true,
|
||||
"handler": "browser_flow"
|
||||
},
|
||||
{
|
||||
"id": "http:GET:/auth/session:hub_core.security.browser.browser_flow",
|
||||
"kind": "runtime-http",
|
||||
"method": "GET",
|
||||
"path": "/auth/session",
|
||||
"profile": "browser-session",
|
||||
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
|
||||
"source": "hub_core.security.browser",
|
||||
"conditional": true,
|
||||
"handler": "browser_flow"
|
||||
},
|
||||
{
|
||||
"id": "http:GET:/console:hub_core.runtime.compat.console",
|
||||
"kind": "runtime-http",
|
||||
|
|
@ -982,6 +1032,17 @@
|
|||
"conditional": false,
|
||||
"handler": "create_widget"
|
||||
},
|
||||
{
|
||||
"id": "http:POST:/auth/logout:hub_core.security.browser.browser_flow",
|
||||
"kind": "runtime-http",
|
||||
"method": "POST",
|
||||
"path": "/auth/logout",
|
||||
"profile": "browser-session",
|
||||
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
|
||||
"source": "hub_core.security.browser",
|
||||
"conditional": true,
|
||||
"handler": "browser_flow"
|
||||
},
|
||||
{
|
||||
"id": "http:POST:/decision-records:hub_core.runtime.compat.accept_deferred",
|
||||
"kind": "runtime-http",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue