feat(makelore): add platform oidc login
This commit is contained in:
1 parent
87d3f03d75
commit
7236def07d
12 files changed
+528
-10
No files matched your search
@@ -0,0 +1,53 @@
|
||||
# Task: Makelore platform SSO client integration
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20261010-makelore-platform-sso-a1b2
|
||||
- Mode: Feature
|
||||
- Branch: codex/20261010-makelore-platform-sso-a1b2-20261010-makelore-platform-sso-a1b2
|
||||
- Worktree: D:\Datas\OthersProjects\.codex-worktrees\makelore\20261010-makelore-platform-sso-a1b2
|
||||
- Base commit: 87d3f03d751b93b607e56d3667c3655f2a03a792
|
||||
- Owner: codex-client-integrations
|
||||
- Status: In Progress
|
||||
|
||||
## Scope
|
||||
|
||||
- Replace the Makelore client’s direct one-feel password/mobile proxy as the primary sign-in path with a platform OIDC Authorization Code flow using PKCE S256.
|
||||
- Keep the flow in Electron Main: generate state and verifier, open the system browser, accept only an authorization code on `niancode://auth/callback`, exchange it against the platform token endpoint, and keep refresh credentials in Main’s existing secure session store.
|
||||
- Project the platform identity (`sub=platform:<UUID>`, `user_id=<platform UUID>`, issuer/audience) into the existing Renderer auth state without copying browser refresh credentials or changing LMS, payment, or server migration behavior.
|
||||
- Add focused Main/deep-link/session tests and update the owning product documentation for the new login boundary.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- The parent platform contract is authoritative: issuer comes from `platform_auth_issuer`; discovery, JWKS, authorize, token, userinfo, and revoke use the standard `/api/auth/oauth/*` paths; Makelore audience defaults to `works-square-api`.
|
||||
- The desktop client uses the system browser and PKCE S256. Client secrets, if the registered desktop client requires one, remain Main-owned and are read from OS-protected configuration; Renderer never receives them.
|
||||
- A callback carries `code` and `state` only. Access/refresh tokens in a deep-link are rejected. State is single-use and bound to the generated verifier and redirect URI.
|
||||
- Existing Main session refresh, account partitioning, logout, and Renderer capability projection remain the owners of local session behavior.
|
||||
- Do not infer identity by username, email, or legacy `auth_user_id`; preserve any legacy identifiers only as opaque migration metadata. Do not deploy, migrate real data, or modify the LMS.
|
||||
- Other active Makelore tasks concern marketplace, fullscreen, teacher concurrency, WeChat diagnosis, or review-only work; none owns auth routes, deep-link parsing, or session storage. Gate result: Passed.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added a Main-owned platform OIDC Authorization Code + PKCE flow. Main discovers the platform authorization and token endpoints, generates one-time state/nonce/verifier values, opens the system browser through the renderer-safe Host API route, accepts the registered `niancode://auth/callback` code/state redirect, cleans the previous local runtime, and persists the returned Works Square session. The callback correlates by state because the platform redirect does not append the legacy desktop `request_id`; legacy request-id-only links remain accepted for compatibility.
|
||||
- Added explicit `/api/auth/platform/start` Host API routing, a platform login action on the native login page, and renderer account rehydration from `/api/auth/me` after Main commits the callback session. Access/refresh credentials remain Main-owned.
|
||||
- Updated the product README and added focused tests for callback parsing, discovery/PKCE/replay, route projection, and login-page browser launch.
|
||||
|
||||
## Verification
|
||||
|
||||
- Planning gate passed after reading the project positioning, current state, decision index, system overview, data flow, module map, business rules, stale-items, commitments, and peer task records.
|
||||
- `pnpm exec vitest run tests/unit/app-deep-link.test.ts tests/unit/platform-auth.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx --maxWorkers=1` (65 tests passed).
|
||||
- `pnpm run typecheck` passed.
|
||||
- `pnpm run lint:check -- electron/main/app-deep-link.ts electron/services/platform-auth.ts electron/api/routes/auth.ts electron/main/index.ts src/App.tsx src/pages/Login/index.tsx tests/unit/app-deep-link.test.ts tests/unit/platform-auth.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx` passed with eight pre-existing warnings outside the changed files and no errors.
|
||||
- Production deployment, real-account migration, and LMS changes were not performed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- The platform issuer/client configuration must be supplied in the packaged deployment (`PLATFORM_AUTH_ISSUER`, with optional `PLATFORM_AUTH_CLIENT_ID`/`PLATFORM_AUTH_SCOPE`); this local task intentionally does not deploy or register clients.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. The product README documents the implemented client behavior; shared architecture promotion remains owned by the parent integration task.
|
||||
|
||||
## Status
|
||||
|
||||
Ready for Integration
|
||||
Reference in new issue
Block a user