feat: add OIDC browser sessions with live access enforcement
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:17:16 +02:00
parent fdea2f5192
commit a15fe032b0
14 changed files with 807 additions and 31 deletions

View file

@ -118,6 +118,23 @@
"audience": "none: minimal process liveness",
"test_owner": "hub-core",
"enforcement": "No identity required; no sensitive details"
},
"browser-session": {
"actor_tenant": "tenant:platform for root; named workload tenant otherwise",
"target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited",
"action_resource_rule": "hub.browser.session for login/session authority; protected API uses existing route action",
"cases": [
"ROOT",
"OTHER",
"INVALID",
"REVOKE",
"OUTAGE",
"BYPASS",
"CALLER"
],
"audience": "hub-browser (OIDC ID token); hub-core (access token); deployment registration required",
"test_owner": "hub-core",
"enforcement": "Explicit BrowserSessions: login is public initiation; callback requires one-time browser-bound state, PKCE and nonce; session requires current authority; logout requires session and CSRF"
}
},
"acceptance_cases": {
@ -399,6 +416,39 @@
"conditional": false,
"handler": "list_widgets"
},
{
"id": "http:GET:/auth/callback:hub_core.security.browser.browser_flow",
"kind": "runtime-http",
"method": "GET",
"path": "/auth/callback",
"profile": "browser-session",
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
"source": "hub_core.security.browser",
"conditional": true,
"handler": "browser_flow"
},
{
"id": "http:GET:/auth/login:hub_core.security.browser.browser_flow",
"kind": "runtime-http",
"method": "GET",
"path": "/auth/login",
"profile": "browser-session",
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
"source": "hub_core.security.browser",
"conditional": true,
"handler": "browser_flow"
},
{
"id": "http:GET:/auth/session:hub_core.security.browser.browser_flow",
"kind": "runtime-http",
"method": "GET",
"path": "/auth/session",
"profile": "browser-session",
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
"source": "hub_core.security.browser",
"conditional": true,
"handler": "browser_flow"
},
{
"id": "http:GET:/console:hub_core.runtime.compat.console",
"kind": "runtime-http",
@ -982,6 +1032,17 @@
"conditional": false,
"handler": "create_widget"
},
{
"id": "http:POST:/auth/logout:hub_core.security.browser.browser_flow",
"kind": "runtime-http",
"method": "POST",
"path": "/auth/logout",
"profile": "browser-session",
"current_gate": "OIDC state/PKCE callback or server-side session; explicit browser composition only",
"source": "hub_core.security.browser",
"conditional": true,
"handler": "browser_flow"
},
{
"id": "http:POST:/decision-records:hub_core.runtime.compat.accept_deferred",
"kind": "runtime-http",