Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
43 lines
2.6 KiB
Markdown
43 lines
2.6 KiB
Markdown
# HUB-WP-0012 browser source evidence — 2026-09-28
|
||
|
||
This is local implementation evidence, not live identity, entitlement, policy,
|
||
archive-custody or deployment acceptance.
|
||
|
||
Implemented explicit browser composition with confidential OIDC code exchange,
|
||
S256 PKCE, one-time browser-bound state, signed ID-token validation, nonce,
|
||
authentication freshness, optional access-token hash binding and live root
|
||
access authorization before session creation. Secure host-only cookies contain
|
||
opaque IDs; tokens remain in bounded process-local memory. Sessions last no
|
||
longer than five minutes or either token, and restart invalidates them.
|
||
Cookie writes require exact Origin and CSRF; every protected request still
|
||
rechecks identity/facts/policy/audit. Session validity is rechecked after authority
|
||
awaits. Local logout remains available during owner outages. Browser refusal
|
||
records exclude authorization codes, tokens and query parameters.
|
||
|
||
Two additional regressions are fixed: explicit controllers cannot silently run
|
||
without enforcement, and slow request bodies time out before authority/handlers.
|
||
|
||
Validation:
|
||
|
||
- `HUB_CORE_AUDIT_CORE_SOURCE=/home/worsch/audit-core .venv/bin/python -m pytest -q --disable-warnings`:
|
||
**328 passed**, one existing Starlette/httpx deprecation warning.
|
||
- After the final correlation-ID adjustment, the browser suite passed again:
|
||
**22 passed**. It uses actual RSA signatures, mock OIDC discovery/code exchange
|
||
and synthetic authority/policy/audit owners. It covers replay/browser binding,
|
||
bad nonce/audience/subject/authorized party/type/time/hash, non-root/non-platform/
|
||
non-MFA denial, expiry/restart, grant withdrawal, CSRF and mixed credentials,
|
||
logout during authority awaits, capacity and owner outage denial. A real native
|
||
message handler accepts a valid session write and refuses a spoofed sender.
|
||
- Wheel/source distribution build passes; the browser module is packaged.
|
||
- Inventory drift/coverage check passes: **165 Hub source surfaces**, 48 platform
|
||
rows and 250 dated cluster objects. Four optional browser protocol routes have
|
||
their own profile; inventory coverage is not live conformance.
|
||
- `git diff --check` passes.
|
||
|
||
Remaining gates: confidential issuer registration and real MFA behavior, immutable
|
||
root and authoritative owner-facts integration, Hub policy admission including
|
||
`hub.browser.session`, durable production audit delivery, proxy logging/rate limits,
|
||
consumer adoption and complete platform acceptance. The source candidate provides
|
||
neither distributed sessions, upstream IdP logout, automatic renewal nor operation
|
||
completion auditing. T01–T04 remain in progress. No public listener or production
|
||
entitlement changed.
|