key-cape/workplans/KEY-WP-0007-user-engine-portal-oidc-client.md
tegwick e8b4eded88
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 26s
Map explicit tenant groups into OIDC claims
2026-07-28 00:34:19 +02:00

63 lines
1.9 KiB
Markdown

---
id: KEY-WP-0007
type: workplan
title: "User-engine portal OIDC relying-party integration"
domain: infotech
repo: key-cape
status: active
owner: codex
topic_slug: netkingdom
created: "2026-07-27"
updated: "2026-07-27"
depends_on:
- KEY-WP-0005
- USER-WP-0020
---
# KEY-WP-0007 - User-engine portal OIDC relying-party integration
Register and prove the reusable user-engine portal as a strict KeyCape public
client. This is the authentication edge required by `NK-WP-0023-T03`; it does
not move user-domain or authorization ownership into KeyCape.
## Register the static portal client
```task
id: KEY-WP-0007-T01
status: done
priority: high
```
Register `user-engine-portal` for authorization code with mandatory S256 PKCE,
exact callback URIs and only `openid profile email groups`. No wildcard,
implicit flow, client secret, or dynamic registration is allowed.
## Deploy and verify the live client
```task
id: KEY-WP-0007-T02
status: done
priority: high
```
Update the railiance01 KeyCape configuration without exposing its signing key
or backend credentials. Verify discovery, authorize redirect validation,
unregistered callback denial and successful token exchange through the portal.
## Prove claims and MFA isolation
```task
id: KEY-WP-0007-T03
status: progress
priority: high
```
Prove issuer, audience, tenant, groups, roles and assurance claims are verified
by the portal and that tenant administration does not imply platform-root.
Complete the Binky user/MFA acceptance through the reusable browser path.
2026-07-27: The live client accepts only the exact portal callback and rejects
an unregistered callback with `invalid_profile_usage`. The portal begins an
S256 PKCE flow and hands authentication to Authelia. LLDAP tenant envelope
mapping now recognizes unambiguous `tenant:<kind>:<slug>:users|admins` groups;
ambiguous multi-tenant directory envelopes fail closed to no explicit tenant.