feat: add OIDC browser sessions with live access enforcement
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
fdea2f5192
commit
a15fe032b0
14 changed files with 807 additions and 31 deletions
|
|
@ -250,7 +250,8 @@ invented and no live service, grant or public listener was changed.
|
|||
complete per-service routes or substitute for the named owners' review.
|
||||
- T02: implemented IAM v0.3 access-token verification with discovery, signature,
|
||||
audience/type/lifetime/assurance validation and rotating keys. Live root binding,
|
||||
PKCE sessions/MFA/logout and authoritative account/tenant adapters remain open.
|
||||
issuer MFA/registration acceptance and authoritative account/tenant adapters remain open.
|
||||
Local PKCE/session/logout implementation is covered in the continuation below.
|
||||
- T03: implemented authenticated workload PDP calls, trusted rotating public keys,
|
||||
signed envelope, submitted request digest, caller/structured binding/lifetime
|
||||
checks and fail-closed obligations. Real Go fixtures prove interoperability.
|
||||
|
|
@ -302,6 +303,28 @@ wheel build and inventory validation pass.
|
|||
T01–T04 remain `progress`; live owner acceptance and the later milestones remain
|
||||
open. No production deployment, entitlement or public listener changed.
|
||||
|
||||
## Browser and enforcement continuation — 2026-09-28
|
||||
|
||||
Closed two local enforcement gaps: injecting a controller into a development
|
||||
runtime now fails startup instead of silently ignoring it, and request bodies
|
||||
have a bounded receive deadline before authority evaluation.
|
||||
|
||||
Added explicit confidential OIDC browser composition with S256 PKCE, one-time
|
||||
browser-bound state, nonce and ID-token checks, fresh MFA/root authorization,
|
||||
opaque short-lived server-side sessions, CSRF protection and local logout.
|
||||
Every protected session request retains live owner/policy/audit checks, including
|
||||
a second session-validity check after authority awaits. Tokens never appear in
|
||||
browser responses. Session/process lifetime, proxy logging and multiworker limits
|
||||
are documented in the [integration guide](../docs/owner-access-integration.md).
|
||||
|
||||
Browser source tests cover actual RSA signatures and code exchange with mocked
|
||||
owner endpoints; they are not live owner acceptance. The source inventory now
|
||||
contains 165 Hub surfaces, including four optional browser protocol routes.
|
||||
[Validation evidence](../docs/evidence/hub-wp-0012-browser-20260928.md).
|
||||
T01–T04 remain `progress`; issuer registration/MFA, owner-facts composition,
|
||||
MCP consumer adoption, operation-outcome auditing and platform conformance remain
|
||||
open. No production listener or entitlement changed.
|
||||
|
||||
## Acceptance checkpoints
|
||||
|
||||
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core
|
||||
|
|
@ -310,5 +333,5 @@ open. No production deployment, entitlement or public listener changed.
|
|||
- [ ] T07: authenticated public exposure separately approved and verified
|
||||
- [ ] Phase 2: T08 delegated and tenant-scoped access accepted
|
||||
|
||||
Planning completion is not implementation completion. No authenticated root
|
||||
Planning completion is not implementation completion. No live authenticated root
|
||||
session or entitlement was tested in the 2026-09-28 review.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue