key-cape/workplans/KEY-WP-0007-user-engine-portal-oidc-client.md

1.5 KiB

id type title domain repo status owner topic_slug created updated depends_on
KEY-WP-0007 workplan User-engine portal OIDC relying-party integration infotech key-cape active codex netkingdom 2026-07-27 2026-07-27
KEY-WP-0005
USER-WP-0020

KEY-WP-0007 - User-engine portal OIDC relying-party integration

Register and prove the reusable user-engine portal as a strict KeyCape public client. This is the authentication edge required by NK-WP-0023-T03; it does not move user-domain or authorization ownership into KeyCape.

Register the static portal client

id: KEY-WP-0007-T01
status: progress
priority: high

Register user-engine-portal for authorization code with mandatory S256 PKCE, exact callback URIs and only openid profile email groups. No wildcard, implicit flow, client secret, or dynamic registration is allowed.

Deploy and verify the live client

id: KEY-WP-0007-T02
status: wait
priority: high

Update the railiance01 KeyCape configuration without exposing its signing key or backend credentials. Verify discovery, authorize redirect validation, unregistered callback denial and successful token exchange through the portal.

Prove claims and MFA isolation

id: KEY-WP-0007-T03
status: wait
priority: high

Prove issuer, audience, tenant, groups, roles and assurance claims are verified by the portal and that tenant administration does not imply platform-root. Complete the Binky user/MFA acceptance through the reusable browser path.