docs(makelore): integrate platform oidc boundary

This commit is contained in:
brother7 committed 2026-10-10 19:42:24 +08:00
1 parent 86216b8458
commit afaefdca6b
6 files changed
+59 -9

No files matched your search

@@ -0,0 +1,46 @@
# Task: Integrate Makelore platform SSO
## Identity
- Task ID: 20261010-integrate-makelore-platform-sso-9c2d
- Mode: Integration
- Branch: main
- Worktree: D:\Datas\OthersProjects\makelore
- Base commit: 87d3f03d751b93b607e56d3667c3655f2a03a792
- Owner: codex-client-integrations
- Status: Ready for Integration
## Scope
- Integrate source task `20261010-makelore-platform-sso-a1b2` at `7236def07d6a9a5cfde70c3239c6ac53764bcd7d` into local `main`; the source registration correction is `86216b8458db9a2c58850a6835fd1a76cee5a846`.
- Reconcile the platform OIDC client boundary across the Makelore system overview, data flow, ADR-004, decision index, and current state. Preserve the existing Works Square password/mobile facade and the unchanged LMS/payment boundary.
- Preserve the three adopted untracked documents byte-for-byte and exclude them from this integration commit: `30-worklog/tasks/20260901-package-122-c5e8.md`, `30-worklog/tasks/20260901-package-123-d7f3.md`, and `30-worklog/tasks/20260902-client-hang-diagnosis-a47c9e2b.md`.
## Intent And Constraints
- Electron Main owns the system-browser OIDC Authorization Code + PKCE flow, token exchange, refresh, and logout projection; require state, nonce, PKCE S256, and exact `niancode://auth/callback`.
- Use the configured platform issuer and stable identity `issuer + sub=platform:<UUID>`; do not rebind by username, email, or legacy `auth_user_id`. Makelore's registered audience remains `works-square-api`.
- Keep confidential OAuth secrets out of the Renderer and packaged public client. Do not call the custom one-feel identity service directly from the client. Do not deploy, push, migrate real accounts, or alter LMS/payment behavior.
- Integration mode owns canonical project-memory reconciliation; the imported source task record remains source evidence and is not rewritten from this task.
## Outcome
- Source implementation and its corrected Ready for Integration registration are fast-forwarded into `main`.
- Canonical architecture and decision records now describe platform OIDC PKCE alongside the retained Works Square legacy authentication facade.
- The three adopted foreign documents remain unchanged and untracked; none is staged by this task.
## Verification
- `check_project_docs.py` passed before planning; Concurrent Task Gate and Planning Gate passed for this integration task.
- Source evidence reused: 65 focused Makelore tests, `pnpm run typecheck`, and scoped lint passed at source `7236def`; no duplicate full suite or package build was needed for this documentation-only reconciliation.
- Fast-forward merge and source task drift passed; final integration runs `git diff --check` and `check_doc_drift.py --task-id 20261010-integrate-makelore-platform-sso-9c2d`.
- No deployment, provider/real-account validation, push, package release, LMS change, payment change, or real-data migration was performed.
## Follow-ups
- Deployment must provide `PLATFORM_AUTH_ISSUER`, the registered Makelore public client, exact `niancode://auth/callback` redirect, and the configured `works-square-api` audience before packaged platform login is released.
- The Makelore source branch and worktree remain retained because cleanup was not authorized for this repository; no production migration is implied.
## Promotion Candidates
- None pending; the OIDC boundary is recorded in ADR-004, `system-overview.md`, `data-flow.md`, and `current-state.md`.