hub-core/docs/evidence/hub-wp-0012-browser-20260928.md
tegwick a15fe032b0
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s
feat: add OIDC browser sessions with live access enforcement
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
2026-09-28 12:17:16 +02:00

43 lines
2.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# HUB-WP-0012 browser source evidence — 2026-09-28
This is local implementation evidence, not live identity, entitlement, policy,
archive-custody or deployment acceptance.
Implemented explicit browser composition with confidential OIDC code exchange,
S256 PKCE, one-time browser-bound state, signed ID-token validation, nonce,
authentication freshness, optional access-token hash binding and live root
access authorization before session creation. Secure host-only cookies contain
opaque IDs; tokens remain in bounded process-local memory. Sessions last no
longer than five minutes or either token, and restart invalidates them.
Cookie writes require exact Origin and CSRF; every protected request still
rechecks identity/facts/policy/audit. Session validity is rechecked after authority
awaits. Local logout remains available during owner outages. Browser refusal
records exclude authorization codes, tokens and query parameters.
Two additional regressions are fixed: explicit controllers cannot silently run
without enforcement, and slow request bodies time out before authority/handlers.
Validation:
- `HUB_CORE_AUDIT_CORE_SOURCE=/home/worsch/audit-core .venv/bin/python -m pytest -q --disable-warnings`:
**328 passed**, one existing Starlette/httpx deprecation warning.
- After the final correlation-ID adjustment, the browser suite passed again:
**22 passed**. It uses actual RSA signatures, mock OIDC discovery/code exchange
and synthetic authority/policy/audit owners. It covers replay/browser binding,
bad nonce/audience/subject/authorized party/type/time/hash, non-root/non-platform/
non-MFA denial, expiry/restart, grant withdrawal, CSRF and mixed credentials,
logout during authority awaits, capacity and owner outage denial. A real native
message handler accepts a valid session write and refuses a spoofed sender.
- Wheel/source distribution build passes; the browser module is packaged.
- Inventory drift/coverage check passes: **165 Hub source surfaces**, 48 platform
rows and 250 dated cluster objects. Four optional browser protocol routes have
their own profile; inventory coverage is not live conformance.
- `git diff --check` passes.
Remaining gates: confidential issuer registration and real MFA behavior, immutable
root and authoritative owner-facts integration, Hub policy admission including
`hub.browser.session`, durable production audit delivery, proxy logging/rate limits,
consumer adoption and complete platform acceptance. The source candidate provides
neither distributed sessions, upstream IdP logout, automatic renewal nor operation
completion auditing. T01–T04 remain in progress. No public listener or production
entitlement changed.