Files
makelore/.project-docs/30-worklog/tasks/20261010-makelore-platform-sso-a1b2.md
T

4.7 KiB
Raw Blame History

Task: Makelore platform SSO client integration

Identity

  • Task ID: 20261010-makelore-platform-sso-a1b2
  • Mode: Feature
  • Branch: codex/20261010-makelore-platform-sso-a1b2-20261010-makelore-platform-sso-a1b2
  • Worktree: D:\Datas\OthersProjects.codex-worktrees\makelore\20261010-makelore-platform-sso-a1b2
  • Base commit: 87d3f03d75
  • Owner: codex-client-integrations
  • Status: Ready for Integration

Scope

  • Replace the Makelore client’s direct one-feel password/mobile proxy as the primary sign-in path with a platform OIDC Authorization Code flow using PKCE S256.
  • Keep the flow in Electron Main: generate state and verifier, open the system browser, accept only an authorization code on niancode://auth/callback, exchange it against the platform token endpoint, and keep refresh credentials in Main’s existing secure session store.
  • Project the platform identity (sub=platform:<UUID>, user_id=<platform UUID>, issuer/audience) into the existing Renderer auth state without copying browser refresh credentials or changing LMS, payment, or server migration behavior.
  • Add focused Main/deep-link/session tests and update the owning product documentation for the new login boundary.

Intent And Constraints

  • The parent platform contract is authoritative: issuer comes from platform_auth_issuer; discovery, JWKS, authorize, token, userinfo, and revoke use the standard /api/auth/oauth/* paths; Makelore audience defaults to works-square-api.
  • The desktop client uses the system browser and PKCE S256. Client secrets, if the registered desktop client requires one, remain Main-owned and are read from OS-protected configuration; Renderer never receives them.
  • A callback carries code and state only. Access/refresh tokens in a deep-link are rejected. State is single-use and bound to the generated verifier and redirect URI.
  • Existing Main session refresh, account partitioning, logout, and Renderer capability projection remain the owners of local session behavior.
  • Do not infer identity by username, email, or legacy auth_user_id; preserve any legacy identifiers only as opaque migration metadata. Do not deploy, migrate real data, or modify the LMS.
  • Other active Makelore tasks concern marketplace, fullscreen, teacher concurrency, WeChat diagnosis, or review-only work; none owns auth routes, deep-link parsing, or session storage. Gate result: Passed.

Outcome

  • Added a Main-owned platform OIDC Authorization Code + PKCE flow. Main discovers the platform authorization and token endpoints, generates one-time state/nonce/verifier values, opens the system browser through the renderer-safe Host API route, accepts the registered niancode://auth/callback code/state redirect, cleans the previous local runtime, and persists the returned Works Square session. The callback correlates by state because the platform redirect does not append the legacy desktop request_id; legacy request-id-only links remain accepted for compatibility.
  • Added explicit /api/auth/platform/start Host API routing, a platform login action on the native login page, and renderer account rehydration from /api/auth/me after Main commits the callback session. Access/refresh credentials remain Main-owned.
  • Updated the product README and added focused tests for callback parsing, discovery/PKCE/replay, route projection, and login-page browser launch.

Verification

  • Planning gate passed after reading the project positioning, current state, decision index, system overview, data flow, module map, business rules, stale-items, commitments, and peer task records.
  • pnpm exec vitest run tests/unit/app-deep-link.test.ts tests/unit/platform-auth.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx --maxWorkers=1 (65 tests passed).
  • pnpm run typecheck passed.
  • pnpm run lint:check -- electron/main/app-deep-link.ts electron/services/platform-auth.ts electron/api/routes/auth.ts electron/main/index.ts src/App.tsx src/pages/Login/index.tsx tests/unit/app-deep-link.test.ts tests/unit/platform-auth.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx passed with eight pre-existing warnings outside the changed files and no errors.
  • Production deployment, real-account migration, and LMS changes were not performed.

Follow-ups

  • The platform issuer/client configuration must be supplied in the packaged deployment (PLATFORM_AUTH_ISSUER, with optional PLATFORM_AUTH_CLIENT_ID/PLATFORM_AUTH_SCOPE); this local task intentionally does not deploy or register clients.

Promotion Candidates

  • None. The product README documents the implemented client behavior; shared architecture promotion remains owned by the parent integration task.

Status

Ready for Integration