docs(integration): record Square auth lifecycle merge
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
# ADR-004: Works Square Owns The Desktop Authentication Lifecycle Boundary
|
||||
|
||||
## Status
|
||||
|
||||
Accepted and implemented on 2026-08-19.
|
||||
|
||||
## Context
|
||||
|
||||
The desktop client obtained tokens from Works Square but refreshed them directly against the custom identity service with an embedded OAuth client secret. That mixed issuer/client boundary made rotation dependent on two independently configured clients and could turn an otherwise valid persisted session into `invalid_grant`, returning the user to the login page hours later.
|
||||
|
||||
## Decision
|
||||
|
||||
- Renderer sends authentication operations only to Electron Main.
|
||||
- Electron Main owns access/refresh tokens, encrypted persistence, refresh rotation, terminal failure cleanup, and the seven-day inactivity policy.
|
||||
- Desktop login, mobile login, refresh, and logout use fixed Works Square `/api/auth/*` endpoints.
|
||||
- Works Square owns the confidential upstream OAuth client configuration and proxies the lifecycle to the identity service.
|
||||
- The desktop bundle must not contain an OAuth client secret or call the custom identity service directly.
|
||||
|
||||
## Consequences
|
||||
|
||||
- The matching Works Square server endpoints must be deployed before this client is released.
|
||||
- OAuth credential rotation or upstream endpoint changes are server-side configuration changes rather than desktop releases.
|
||||
- A terminal refresh `400` or `401` still fails closed and clears the local session; transient failures preserve the established retry behavior.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Source commit: `dc776ff`
|
||||
- Integration merge: `f52c2c8`
|
||||
- Feature verification: 2,190 client tests passed, typecheck passed, Vite build passed, and lint reported no errors.
|
||||
@@ -7,6 +7,7 @@
|
||||
| ADR-001 | AI 绘画采用 Workspace / Conversation / Task 分层状态与服务端持久 Conversation Session | Accepted | 2026-08-11 | AI 绘画客户端、Main 适配器、Works Square API | `adr-001-ai-design-conversation-ownership.md` |
|
||||
| ADR-002 | Robot V1 采用 Main 门控的引导式热点配网并衔接现有六位 Binding | Accepted / implemented, default on | 2026-08-16 | Robot Renderer、Host API、Electron Main、现有固件热点入口 | `adr-002-robot-guided-hotspot-binding-v1.md` |
|
||||
| ADR-003 | Robot 配网页内扫描并连接 Windows/macOS 热点 | Accepted / implemented with physical release gates pending | 2026-08-16 | Robot Renderer、Host API、Electron Main、Windows WLAN、macOS CoreWLAN/CoreLocation | `adr-003-robot-in-app-hotspot-connection.md` |
|
||||
| ADR-004 | Works Square 统一拥有桌面认证生命周期边界 | Accepted / implemented | 2026-08-19 | Renderer、Host API、Electron Main、Works Square auth facade | `adr-004-square-auth-lifecycle-boundary.md` |
|
||||
|
||||
## Superseded Decisions
|
||||
|
||||
|
||||
Reference in New Issue
Block a user