docs(makelore): integrate platform oidc boundary

This commit is contained in:
brother7 committed 2026-10-10 19:42:24 +08:00
1 parent 86216b8458
commit afaefdca6b
6 files changed
+59 -9

No files matched your search

@@ -2,25 +2,27 @@
## Status
Accepted and implemented on 2026-08-19.
Accepted and implemented on 2026-08-19; amended on 2026-10-10.
## Context
The desktop client obtained tokens from Works Square but refreshed them directly against the custom identity service with an embedded OAuth client secret. That mixed issuer/client boundary made rotation dependent on two independently configured clients and could turn an otherwise valid persisted session into `invalid_grant`, returning the user to the login page hours later.
The desktop client obtained tokens from Works Square but refreshed them directly against the custom identity service with an embedded OAuth client secret. That mixed issuer/client boundary made rotation dependent on two independently configured clients and could turn an otherwise valid persisted session into `invalid_grant`, returning the user to the login page hours later. The platform account system now exposes a standard OIDC issuer for the public platform identity while the existing Works Square password/mobile facade remains available for its legacy path.
## Decision
- Renderer sends authentication operations only to Electron Main.
- Electron Main owns access/refresh tokens, encrypted persistence, refresh rotation, terminal failure cleanup, and the seven-day inactivity policy.
- Optional remembered username/password data is a separate Electron Main record. Packaged builds encrypt it with OS-protected storage; it is never Renderer-persisted or stored by Works Square.
- Desktop login, mobile login, refresh, and logout use fixed Works Square `/api/auth/*` endpoints.
- Platform account login uses Main-owned Authorization Code + PKCE against the configured platform OIDC issuer: system browser, exact `niancode://auth/callback`, state/nonce/S256 validation, and a registered public Makelore client without a secret. Main owns the code exchange and all resulting tokens.
- Legacy password/mobile login, refresh, and logout use fixed Works Square `/api/auth/*` endpoints.
- Works Square owns the confidential upstream OAuth client configuration and proxies the lifecycle to the identity service.
- The desktop bundle must not contain an OAuth client secret or call the custom identity service directly.
- The desktop bundle must not contain a confidential OAuth client secret or call the custom one-feel identity service directly; platform OIDC access remains behind the Main boundary and uses the configured standard issuer.
- Logout and mobile login preserve remembered-password data. A successful password login with the option cleared removes the previous record; unavailable secure storage disables the option.
## Consequences
- The matching Works Square server endpoints must be deployed before this client is released.
- The packaged client must receive `PLATFORM_AUTH_ISSUER` and the registered Makelore client/redirect configuration before platform login can be released; no username, email, or legacy identifier is used to rebind a platform subject.
- OAuth credential rotation or upstream endpoint changes are server-side configuration changes rather than desktop releases.
- A terminal refresh `400` or `401` still fails closed and clears the local session; transient failures preserve the established retry behavior.
- Remembered-password persistence is convenience behavior rather than session authority. Its failure must not grant authentication or move password persistence to Works Square/Renderer.
+1 -1
View File
@@ -36,7 +36,7 @@
| ADR-007 | AI Design 采用单一 Current Specification、Living Form 与不可变 Quote 的 V2 权威;active plan 与 reference alias 是其公共投影 | Accepted / implemented, amended 2026-09-07 | 2026-08-30 | AI Design Renderer、Electron Main、Works Square V2 API | `adr-007-ai-design-living-form-v2.md` |
| ADR-002 | Robot V1 采用 Main 门控的引导式热点配网并衔接现有六位 Binding | Accepted / implemented, default on | 2026-08-16 | Robot Renderer、Host API、Electron Main、现有固件热点入口 | `adr-002-robot-guided-hotspot-binding-v1.md` |
| ADR-003 | Robot 配网页内扫描并连接 Windows/macOS 热点 | Accepted / implemented with physical release gates pending | 2026-08-16 | Robot Renderer、Host API、Electron Main、Windows WLAN、macOS CoreWLAN/CoreLocation | `adr-003-robot-in-app-hotspot-connection.md` |
| ADR-004 | Works Square 统一拥有桌面认证生命周期边界 | Accepted / implemented | 2026-08-19 | Renderer、Host API、Electron Main、Works Square auth facade | `adr-004-square-auth-lifecycle-boundary.md` |
| ADR-004 | Works Square 与平台 OIDC 共同由 Electron Main 统一拥有桌面认证生命周期边界 | Accepted / implemented, amended 2026-10-10 | 2026-08-19 | Renderer、Host API、Electron Main、Works Square auth facade、platform OIDC issuer | `adr-004-square-auth-lifecycle-boundary.md` |
| ADR-006 | Makelore Code 以 Pi `0.84.2` 为唯一 runtime,父 Conversation 复用一个 Main-owned Agent Server 并隔离逻辑 Runtime/Session/provider/lease,产品只暴露 Snapshot/Patch 合同 | Accepted / implemented, amended 2026-08-31 | 2026-08-26 | Code Renderer、Host API、Electron Main、Pi runtime、Provider/resource、packaging | `adr-006-pi-runtime-hard-cutover.md` |
## Superseded Decisions