docs(makelore): integrate platform oidc boundary
This commit is contained in:
1 parent
86216b8458
commit
afaefdca6b
6 files changed
+59
-9
No files matched your search
@@ -0,0 +1,46 @@
|
||||
# Task: Integrate Makelore platform SSO
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20261010-integrate-makelore-platform-sso-9c2d
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: D:\Datas\OthersProjects\makelore
|
||||
- Base commit: 87d3f03d751b93b607e56d3667c3655f2a03a792
|
||||
- Owner: codex-client-integrations
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Integrate source task `20261010-makelore-platform-sso-a1b2` at `7236def07d6a9a5cfde70c3239c6ac53764bcd7d` into local `main`; the source registration correction is `86216b8458db9a2c58850a6835fd1a76cee5a846`.
|
||||
- Reconcile the platform OIDC client boundary across the Makelore system overview, data flow, ADR-004, decision index, and current state. Preserve the existing Works Square password/mobile facade and the unchanged LMS/payment boundary.
|
||||
- Preserve the three adopted untracked documents byte-for-byte and exclude them from this integration commit: `30-worklog/tasks/20260901-package-122-c5e8.md`, `30-worklog/tasks/20260901-package-123-d7f3.md`, and `30-worklog/tasks/20260902-client-hang-diagnosis-a47c9e2b.md`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Electron Main owns the system-browser OIDC Authorization Code + PKCE flow, token exchange, refresh, and logout projection; require state, nonce, PKCE S256, and exact `niancode://auth/callback`.
|
||||
- Use the configured platform issuer and stable identity `issuer + sub=platform:<UUID>`; do not rebind by username, email, or legacy `auth_user_id`. Makelore's registered audience remains `works-square-api`.
|
||||
- Keep confidential OAuth secrets out of the Renderer and packaged public client. Do not call the custom one-feel identity service directly from the client. Do not deploy, push, migrate real accounts, or alter LMS/payment behavior.
|
||||
- Integration mode owns canonical project-memory reconciliation; the imported source task record remains source evidence and is not rewritten from this task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Source implementation and its corrected Ready for Integration registration are fast-forwarded into `main`.
|
||||
- Canonical architecture and decision records now describe platform OIDC PKCE alongside the retained Works Square legacy authentication facade.
|
||||
- The three adopted foreign documents remain unchanged and untracked; none is staged by this task.
|
||||
|
||||
## Verification
|
||||
|
||||
- `check_project_docs.py` passed before planning; Concurrent Task Gate and Planning Gate passed for this integration task.
|
||||
- Source evidence reused: 65 focused Makelore tests, `pnpm run typecheck`, and scoped lint passed at source `7236def`; no duplicate full suite or package build was needed for this documentation-only reconciliation.
|
||||
- Fast-forward merge and source task drift passed; final integration runs `git diff --check` and `check_doc_drift.py --task-id 20261010-integrate-makelore-platform-sso-9c2d`.
|
||||
- No deployment, provider/real-account validation, push, package release, LMS change, payment change, or real-data migration was performed.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Deployment must provide `PLATFORM_AUTH_ISSUER`, the registered Makelore public client, exact `niancode://auth/callback` redirect, and the configured `works-square-api` audience before packaged platform login is released.
|
||||
- The Makelore source branch and worktree remain retained because cleanup was not authorized for this repository; no production migration is implied.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None pending; the OIDC boundary is recorded in ADR-004, `system-overview.md`, `data-flow.md`, and `current-state.md`.
|
||||
Reference in new issue
Block a user