docs(makelore): integrate platform oidc boundary
This commit is contained in:
1 parent
86216b8458
commit
afaefdca6b
6 files changed
+59
-9
No files matched your search
@@ -2,25 +2,27 @@
|
||||
|
||||
## Status
|
||||
|
||||
Accepted and implemented on 2026-08-19.
|
||||
Accepted and implemented on 2026-08-19; amended on 2026-10-10.
|
||||
|
||||
## Context
|
||||
|
||||
The desktop client obtained tokens from Works Square but refreshed them directly against the custom identity service with an embedded OAuth client secret. That mixed issuer/client boundary made rotation dependent on two independently configured clients and could turn an otherwise valid persisted session into `invalid_grant`, returning the user to the login page hours later.
|
||||
The desktop client obtained tokens from Works Square but refreshed them directly against the custom identity service with an embedded OAuth client secret. That mixed issuer/client boundary made rotation dependent on two independently configured clients and could turn an otherwise valid persisted session into `invalid_grant`, returning the user to the login page hours later. The platform account system now exposes a standard OIDC issuer for the public platform identity while the existing Works Square password/mobile facade remains available for its legacy path.
|
||||
|
||||
## Decision
|
||||
|
||||
- Renderer sends authentication operations only to Electron Main.
|
||||
- Electron Main owns access/refresh tokens, encrypted persistence, refresh rotation, terminal failure cleanup, and the seven-day inactivity policy.
|
||||
- Optional remembered username/password data is a separate Electron Main record. Packaged builds encrypt it with OS-protected storage; it is never Renderer-persisted or stored by Works Square.
|
||||
- Desktop login, mobile login, refresh, and logout use fixed Works Square `/api/auth/*` endpoints.
|
||||
- Platform account login uses Main-owned Authorization Code + PKCE against the configured platform OIDC issuer: system browser, exact `niancode://auth/callback`, state/nonce/S256 validation, and a registered public Makelore client without a secret. Main owns the code exchange and all resulting tokens.
|
||||
- Legacy password/mobile login, refresh, and logout use fixed Works Square `/api/auth/*` endpoints.
|
||||
- Works Square owns the confidential upstream OAuth client configuration and proxies the lifecycle to the identity service.
|
||||
- The desktop bundle must not contain an OAuth client secret or call the custom identity service directly.
|
||||
- The desktop bundle must not contain a confidential OAuth client secret or call the custom one-feel identity service directly; platform OIDC access remains behind the Main boundary and uses the configured standard issuer.
|
||||
- Logout and mobile login preserve remembered-password data. A successful password login with the option cleared removes the previous record; unavailable secure storage disables the option.
|
||||
|
||||
## Consequences
|
||||
|
||||
- The matching Works Square server endpoints must be deployed before this client is released.
|
||||
- The packaged client must receive `PLATFORM_AUTH_ISSUER` and the registered Makelore client/redirect configuration before platform login can be released; no username, email, or legacy identifier is used to rebind a platform subject.
|
||||
- OAuth credential rotation or upstream endpoint changes are server-side configuration changes rather than desktop releases.
|
||||
- A terminal refresh `400` or `401` still fails closed and clears the local session; transient failures preserve the established retry behavior.
|
||||
- Remembered-password persistence is convenience behavior rather than session authority. Its failure must not grant authentication or move password persistence to Works Square/Renderer.
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
| ADR-007 | AI Design 采用单一 Current Specification、Living Form 与不可变 Quote 的 V2 权威;active plan 与 reference alias 是其公共投影 | Accepted / implemented, amended 2026-09-07 | 2026-08-30 | AI Design Renderer、Electron Main、Works Square V2 API | `adr-007-ai-design-living-form-v2.md` |
|
||||
| ADR-002 | Robot V1 采用 Main 门控的引导式热点配网并衔接现有六位 Binding | Accepted / implemented, default on | 2026-08-16 | Robot Renderer、Host API、Electron Main、现有固件热点入口 | `adr-002-robot-guided-hotspot-binding-v1.md` |
|
||||
| ADR-003 | Robot 配网页内扫描并连接 Windows/macOS 热点 | Accepted / implemented with physical release gates pending | 2026-08-16 | Robot Renderer、Host API、Electron Main、Windows WLAN、macOS CoreWLAN/CoreLocation | `adr-003-robot-in-app-hotspot-connection.md` |
|
||||
| ADR-004 | Works Square 统一拥有桌面认证生命周期边界 | Accepted / implemented | 2026-08-19 | Renderer、Host API、Electron Main、Works Square auth facade | `adr-004-square-auth-lifecycle-boundary.md` |
|
||||
| ADR-004 | Works Square 与平台 OIDC 共同由 Electron Main 统一拥有桌面认证生命周期边界 | Accepted / implemented, amended 2026-10-10 | 2026-08-19 | Renderer、Host API、Electron Main、Works Square auth facade、platform OIDC issuer | `adr-004-square-auth-lifecycle-boundary.md` |
|
||||
| ADR-006 | Makelore Code 以 Pi `0.84.2` 为唯一 runtime,父 Conversation 复用一个 Main-owned Agent Server 并隔离逻辑 Runtime/Session/provider/lease,产品只暴露 Snapshot/Patch 合同 | Accepted / implemented, amended 2026-08-31 | 2026-08-26 | Code Renderer、Host API、Electron Main、Pi runtime、Provider/resource、packaging | `adr-006-pi-runtime-hard-cutover.md` |
|
||||
|
||||
## Superseded Decisions
|
||||
|
||||
Reference in new issue
Block a user