feat: add OIDC browser sessions with live access enforcement
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:17:16 +02:00
parent fdea2f5192
commit a15fe032b0
14 changed files with 807 additions and 31 deletions

View file

@ -250,7 +250,8 @@ invented and no live service, grant or public listener was changed.
complete per-service routes or substitute for the named owners' review.
- T02: implemented IAM v0.3 access-token verification with discovery, signature,
audience/type/lifetime/assurance validation and rotating keys. Live root binding,
PKCE sessions/MFA/logout and authoritative account/tenant adapters remain open.
issuer MFA/registration acceptance and authoritative account/tenant adapters remain open.
Local PKCE/session/logout implementation is covered in the continuation below.
- T03: implemented authenticated workload PDP calls, trusted rotating public keys,
signed envelope, submitted request digest, caller/structured binding/lifetime
checks and fail-closed obligations. Real Go fixtures prove interoperability.
@ -302,6 +303,28 @@ wheel build and inventory validation pass.
T01–T04 remain `progress`; live owner acceptance and the later milestones remain
open. No production deployment, entitlement or public listener changed.
## Browser and enforcement continuation — 2026-09-28
Closed two local enforcement gaps: injecting a controller into a development
runtime now fails startup instead of silently ignoring it, and request bodies
have a bounded receive deadline before authority evaluation.
Added explicit confidential OIDC browser composition with S256 PKCE, one-time
browser-bound state, nonce and ID-token checks, fresh MFA/root authorization,
opaque short-lived server-side sessions, CSRF protection and local logout.
Every protected session request retains live owner/policy/audit checks, including
a second session-validity check after authority awaits. Tokens never appear in
browser responses. Session/process lifetime, proxy logging and multiworker limits
are documented in the [integration guide](../docs/owner-access-integration.md).
Browser source tests cover actual RSA signatures and code exchange with mocked
owner endpoints; they are not live owner acceptance. The source inventory now
contains 165 Hub surfaces, including four optional browser protocol routes.
[Validation evidence](../docs/evidence/hub-wp-0012-browser-20260928.md).
T01–T04 remain `progress`; issuer registration/MFA, owner-facts composition,
MCP consumer adoption, operation-outcome auditing and platform conformance remain
open. No production listener or entitlement changed.
## Acceptance checkpoints
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core
@ -310,5 +333,5 @@ open. No production deployment, entitlement or public listener changed.
- [ ] T07: authenticated public exposure separately approved and verified
- [ ] Phase 2: T08 delegated and tenant-scoped access accepted
Planning completion is not implementation completion. No authenticated root
Planning completion is not implementation completion. No live authenticated root
session or entitlement was tested in the 2026-09-28 review.