Files
makelore/.project-docs/30-worklog/tasks/20261010-integrate-makelore-platform-sso-9c2d.md
T

3.4 KiB

Task: Integrate Makelore platform SSO

Identity

  • Task ID: 20261010-integrate-makelore-platform-sso-9c2d
  • Mode: Integration
  • Branch: main
  • Worktree: D:\Datas\OthersProjects\makelore
  • Base commit: 87d3f03d75
  • Owner: codex-client-integrations
  • Status: Ready for Integration

Scope

  • Integrate source task 20261010-makelore-platform-sso-a1b2 at 7236def07d6a9a5cfde70c3239c6ac53764bcd7d into local main; the source registration correction is 86216b8458db9a2c58850a6835fd1a76cee5a846.
  • Reconcile the platform OIDC client boundary across the Makelore system overview, data flow, ADR-004, decision index, and current state. Preserve the existing Works Square password/mobile facade and the unchanged LMS/payment boundary.
  • Preserve the three adopted untracked documents byte-for-byte and exclude them from this integration commit: 30-worklog/tasks/20260901-package-122-c5e8.md, 30-worklog/tasks/20260901-package-123-d7f3.md, and 30-worklog/tasks/20260902-client-hang-diagnosis-a47c9e2b.md.

Intent And Constraints

  • Electron Main owns the system-browser OIDC Authorization Code + PKCE flow, token exchange, refresh, and logout projection; require state, nonce, PKCE S256, and exact niancode://auth/callback.
  • Use the configured platform issuer and stable identity issuer + sub=platform:<UUID>; do not rebind by username, email, or legacy auth_user_id. Makelore's registered audience remains works-square-api.
  • Keep confidential OAuth secrets out of the Renderer and packaged public client. Do not call the custom one-feel identity service directly from the client. Do not deploy, push, migrate real accounts, or alter LMS/payment behavior.
  • Integration mode owns canonical project-memory reconciliation; the imported source task record remains source evidence and is not rewritten from this task.

Outcome

  • Source implementation and its corrected Ready for Integration registration are fast-forwarded into main.
  • Canonical architecture and decision records now describe platform OIDC PKCE alongside the retained Works Square legacy authentication facade.
  • The three adopted foreign documents remain unchanged and untracked; none is staged by this task.

Verification

  • check_project_docs.py passed before planning; Concurrent Task Gate and Planning Gate passed for this integration task.
  • Source evidence reused: 65 focused Makelore tests, pnpm run typecheck, and scoped lint passed at source 7236def; no duplicate full suite or package build was needed for this documentation-only reconciliation.
  • Fast-forward merge and source task drift passed; final integration runs git diff --check and check_doc_drift.py --task-id 20261010-integrate-makelore-platform-sso-9c2d.
  • No deployment, provider/real-account validation, push, package release, LMS change, payment change, or real-data migration was performed.

Follow-ups

  • Deployment must provide PLATFORM_AUTH_ISSUER, the registered Makelore public client, exact niancode://auth/callback redirect, and the configured works-square-api audience before packaged platform login is released.
  • The Makelore source branch and worktree remain retained because cleanup was not authorized for this repository; no production migration is implied.

Promotion Candidates

  • None pending; the OIDC boundary is recorded in ADR-004, system-overview.md, data-flow.md, and current-state.md.