Register user-engine portal OIDC client

This commit is contained in:
tegwick 2026-07-28 00:06:38 +02:00
parent 401ab9ca55
commit 993a4dd589
2 changed files with 64 additions and 0 deletions

View file

@ -37,3 +37,10 @@ clients:
allowedScopes: ["openid", "profile", "email", "groups"] allowedScopes: ["openid", "profile", "email", "groups"]
grantTypes: ["authorization_code"] grantTypes: ["authorization_code"]
clientType: "public" clientType: "public"
- clientId: "user-engine-portal"
displayName: "User Engine Portal"
redirectUris:
- "https://users.92-205-62-239.nip.io/oidc/callback"
allowedScopes: ["openid", "profile", "email", "groups"]
grantTypes: ["authorization_code"]
clientType: "public"

View file

@ -0,0 +1,57 @@
---
id: KEY-WP-0007
type: workplan
title: "User-engine portal OIDC relying-party integration"
domain: infotech
repo: key-cape
status: active
owner: codex
topic_slug: netkingdom
created: "2026-07-27"
updated: "2026-07-27"
depends_on:
- KEY-WP-0005
- USER-WP-0020
---
# KEY-WP-0007 - User-engine portal OIDC relying-party integration
Register and prove the reusable user-engine portal as a strict KeyCape public
client. This is the authentication edge required by `NK-WP-0023-T03`; it does
not move user-domain or authorization ownership into KeyCape.
## Register the static portal client
```task
id: KEY-WP-0007-T01
status: progress
priority: high
```
Register `user-engine-portal` for authorization code with mandatory S256 PKCE,
exact callback URIs and only `openid profile email groups`. No wildcard,
implicit flow, client secret, or dynamic registration is allowed.
## Deploy and verify the live client
```task
id: KEY-WP-0007-T02
status: wait
priority: high
```
Update the railiance01 KeyCape configuration without exposing its signing key
or backend credentials. Verify discovery, authorize redirect validation,
unregistered callback denial and successful token exchange through the portal.
## Prove claims and MFA isolation
```task
id: KEY-WP-0007-T03
status: wait
priority: high
```
Prove issuer, audience, tenant, groups, roles and assurance claims are verified
by the portal and that tenant administration does not imply platform-root.
Complete the Binky user/MFA acceptance through the reusable browser path.