Register user-engine portal OIDC client
This commit is contained in:
parent
401ab9ca55
commit
993a4dd589
2 changed files with 64 additions and 0 deletions
|
|
@ -37,3 +37,10 @@ clients:
|
||||||
allowedScopes: ["openid", "profile", "email", "groups"]
|
allowedScopes: ["openid", "profile", "email", "groups"]
|
||||||
grantTypes: ["authorization_code"]
|
grantTypes: ["authorization_code"]
|
||||||
clientType: "public"
|
clientType: "public"
|
||||||
|
- clientId: "user-engine-portal"
|
||||||
|
displayName: "User Engine Portal"
|
||||||
|
redirectUris:
|
||||||
|
- "https://users.92-205-62-239.nip.io/oidc/callback"
|
||||||
|
allowedScopes: ["openid", "profile", "email", "groups"]
|
||||||
|
grantTypes: ["authorization_code"]
|
||||||
|
clientType: "public"
|
||||||
|
|
|
||||||
57
workplans/KEY-WP-0007-user-engine-portal-oidc-client.md
Normal file
57
workplans/KEY-WP-0007-user-engine-portal-oidc-client.md
Normal file
|
|
@ -0,0 +1,57 @@
|
||||||
|
---
|
||||||
|
id: KEY-WP-0007
|
||||||
|
type: workplan
|
||||||
|
title: "User-engine portal OIDC relying-party integration"
|
||||||
|
domain: infotech
|
||||||
|
repo: key-cape
|
||||||
|
status: active
|
||||||
|
owner: codex
|
||||||
|
topic_slug: netkingdom
|
||||||
|
created: "2026-07-27"
|
||||||
|
updated: "2026-07-27"
|
||||||
|
depends_on:
|
||||||
|
- KEY-WP-0005
|
||||||
|
- USER-WP-0020
|
||||||
|
---
|
||||||
|
|
||||||
|
# KEY-WP-0007 - User-engine portal OIDC relying-party integration
|
||||||
|
|
||||||
|
Register and prove the reusable user-engine portal as a strict KeyCape public
|
||||||
|
client. This is the authentication edge required by `NK-WP-0023-T03`; it does
|
||||||
|
not move user-domain or authorization ownership into KeyCape.
|
||||||
|
|
||||||
|
## Register the static portal client
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: KEY-WP-0007-T01
|
||||||
|
status: progress
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Register `user-engine-portal` for authorization code with mandatory S256 PKCE,
|
||||||
|
exact callback URIs and only `openid profile email groups`. No wildcard,
|
||||||
|
implicit flow, client secret, or dynamic registration is allowed.
|
||||||
|
|
||||||
|
## Deploy and verify the live client
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: KEY-WP-0007-T02
|
||||||
|
status: wait
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Update the railiance01 KeyCape configuration without exposing its signing key
|
||||||
|
or backend credentials. Verify discovery, authorize redirect validation,
|
||||||
|
unregistered callback denial and successful token exchange through the portal.
|
||||||
|
|
||||||
|
## Prove claims and MFA isolation
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: KEY-WP-0007-T03
|
||||||
|
status: wait
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Prove issuer, audience, tenant, groups, roles and assurance claims are verified
|
||||||
|
by the portal and that tenant administration does not imply platform-root.
|
||||||
|
Complete the Binky user/MFA acceptance through the reusable browser path.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue