docs(makelore): integrate platform oidc boundary
This commit is contained in:
1 parent
86216b8458
commit
afaefdca6b
6 files changed
+59
-9
No files matched your search
@@ -4,6 +4,8 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- 2026-10-10:按用户确认,将 Makelore 平台 SSO 源 `7236def07d6a9a5cfde70c3239c6ac53764bcd7d` 无冲突快进合入本地 `main`,并修正来源登记提交 `86216b8458db9a2c58850a6835fd1a76cee5a846`。Electron Main 通过系统浏览器使用平台 OIDC Authorization Code + PKCE,校验 state/nonce/S256、精确 `niancode://auth/callback`,并在 Main 内持有 access/refresh token;平台身份按 issuer + `sub=platform:<UUID>` 使用,传统 Works Square 密码/手机登录路径保留。源验证沿用 65 项聚焦测试、typecheck 与变更文件 lint;本次未推送、部署、迁移真实账号、改 LMS 或支付。已有 3 份外来未跟踪文档原样保留且未纳入提交。见[源任务](tasks/20261010-makelore-platform-sso-a1b2.md)和[本次集成](tasks/20261010-integrate-makelore-platform-sso-9c2d.md)。
|
||||
|
||||
- 2026-10-09:按用户要求,将集成源 `35e2a9149aed7d918176f00369cee6528505cdb8` 从 `fe1a3775` 无冲突快进合入本地 `main`。应用、测试、配置与已验证源保持相同,本次仅补充主分支交付记录。原有 3 份外来文档原样保留且未纳入提交;全部源分支和工作区按用户要求保留。未推送、部署、迁移生产数据或发布安装包;真实机构、OSS/网络、支付和设备验收仍待执行。见[本次合并](tasks/20261009-merge-product-dd0461f9.md)。本条更新下方独立分支阶段的未合主分支状态,历史来源记录不改写。
|
||||
|
||||
- 2026-10-09:本独立 integration 分支以实施源 `0d442ce576430880355ca35382b844d2cec14d64` 为基线,整合原创作和永久点数决定及后续用户决定。D01 当前账号充值、可见收款对象及无课程客户端边界已有本地实现;家长登录孩子账号充值、麦洛不体现课程替代旧充值待定/客户端课程提案。应用和测试保持源版本,源记录原样保留。当前正式设计尚未推广到主分支;未部署、支付或删除工作区。本批无客户端迁移。真实机构、OSS/网络、支付或移动验收仍按各项目留项。见[正式设计](../20-architecture/community-collaboration.md)、[实施证据](tasks/20261009-makelore-product-implementation-eaa0ffa5.md)、[本次集成](tasks/20261009-makelore-product-integration-29d647c5.md)。下方日期条目为历史阶段,不以早期未实现/待定描述覆盖本条。
|
||||
@@ -1234,4 +1236,4 @@ Robot 绑定设备默认先显示“引导配网 / 已有激活码”路径选
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-09-29
|
||||
2026-10-10
|
||||
@@ -0,0 +1,46 @@
|
||||
# Task: Integrate Makelore platform SSO
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20261010-integrate-makelore-platform-sso-9c2d
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: D:\Datas\OthersProjects\makelore
|
||||
- Base commit: 87d3f03d751b93b607e56d3667c3655f2a03a792
|
||||
- Owner: codex-client-integrations
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Integrate source task `20261010-makelore-platform-sso-a1b2` at `7236def07d6a9a5cfde70c3239c6ac53764bcd7d` into local `main`; the source registration correction is `86216b8458db9a2c58850a6835fd1a76cee5a846`.
|
||||
- Reconcile the platform OIDC client boundary across the Makelore system overview, data flow, ADR-004, decision index, and current state. Preserve the existing Works Square password/mobile facade and the unchanged LMS/payment boundary.
|
||||
- Preserve the three adopted untracked documents byte-for-byte and exclude them from this integration commit: `30-worklog/tasks/20260901-package-122-c5e8.md`, `30-worklog/tasks/20260901-package-123-d7f3.md`, and `30-worklog/tasks/20260902-client-hang-diagnosis-a47c9e2b.md`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Electron Main owns the system-browser OIDC Authorization Code + PKCE flow, token exchange, refresh, and logout projection; require state, nonce, PKCE S256, and exact `niancode://auth/callback`.
|
||||
- Use the configured platform issuer and stable identity `issuer + sub=platform:<UUID>`; do not rebind by username, email, or legacy `auth_user_id`. Makelore's registered audience remains `works-square-api`.
|
||||
- Keep confidential OAuth secrets out of the Renderer and packaged public client. Do not call the custom one-feel identity service directly from the client. Do not deploy, push, migrate real accounts, or alter LMS/payment behavior.
|
||||
- Integration mode owns canonical project-memory reconciliation; the imported source task record remains source evidence and is not rewritten from this task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Source implementation and its corrected Ready for Integration registration are fast-forwarded into `main`.
|
||||
- Canonical architecture and decision records now describe platform OIDC PKCE alongside the retained Works Square legacy authentication facade.
|
||||
- The three adopted foreign documents remain unchanged and untracked; none is staged by this task.
|
||||
|
||||
## Verification
|
||||
|
||||
- `check_project_docs.py` passed before planning; Concurrent Task Gate and Planning Gate passed for this integration task.
|
||||
- Source evidence reused: 65 focused Makelore tests, `pnpm run typecheck`, and scoped lint passed at source `7236def`; no duplicate full suite or package build was needed for this documentation-only reconciliation.
|
||||
- Fast-forward merge and source task drift passed; final integration runs `git diff --check` and `check_doc_drift.py --task-id 20261010-integrate-makelore-platform-sso-9c2d`.
|
||||
- No deployment, provider/real-account validation, push, package release, LMS change, payment change, or real-data migration was performed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Deployment must provide `PLATFORM_AUTH_ISSUER`, the registered Makelore public client, exact `niancode://auth/callback` redirect, and the configured `works-square-api` audience before packaged platform login is released.
|
||||
- The Makelore source branch and worktree remain retained because cleanup was not authorized for this repository; no production migration is implied.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None pending; the OIDC boundary is recorded in ADR-004, `system-overview.md`, `data-flow.md`, and `current-state.md`.
|
||||
Reference in new issue
Block a user