feat: add OIDC browser sessions with live access enforcement
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:17:16 +02:00
parent fdea2f5192
commit a15fe032b0
14 changed files with 807 additions and 31 deletions

View file

@ -17,6 +17,7 @@ def discover(root):
from hub_core.runtime.app import create_app
from hub_core.runtime.config import RuntimeSettings
from hub_core.runtime.inbox_projection import create_inbox_projection_router
from hub_core.security.browser import create_browser_router
rows = []
@ -31,7 +32,7 @@ def discover(root):
# Construction only: no lifespan/startup and no requests or DB connection.
app = create_app(settings=RuntimeSettings())
for route in [*routes(app), *routes(create_inbox_projection_router())]:
for route in [*routes(app), *routes(create_inbox_projection_router()), *routes(create_browser_router())]:
endpoint = route.endpoint
source = inspect.getsource(endpoint)
module = endpoint.__module__
@ -39,11 +40,14 @@ def discover(root):
else 'no-identity-check-in-handler')
if route.path != '/healthz':
gate = 'access-profile-v1 in enforcement mode; development: ' + gate
browser = module.endswith("security.browser")
if browser:
gate = "OIDC state/PKCE callback or server-side session; explicit browser composition only"
for method in sorted(route.methods):
rows.append(dict(id=f'http:{method}:{route.path}:{module}.{endpoint.__name__}', kind='runtime-http',
method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'hub-api'),
method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'browser-session' if browser else 'hub-api'),
current_gate=gate, source=module,
conditional=module.endswith('inbox_projection'),
conditional=browser or module.endswith('inbox_projection'),
handler=endpoint.__name__))
verbs = {'get', 'post', 'patch', 'put', 'delete', 'head', 'options'}