Skip to content

feat: verify RFC 9068 SSO token management - #489

Merged
sjungwon03 merged 1 commit into
mainfrom
feat/488-sso-token-management
Oct 11, 2026
Merged

sjungwon03 merged 1 commit into
mainfrom
feat/488-sso-token-management

Conversation

@sjungwon03

Copy link
Copy Markdown
Member

Closes #488

Valid SSO access tokens can now drive internal proxy-token issue/revoke without letting a caller nominate the authenticated actor. A real RFC 9068 verifier uses administrator-registered RS256 public JWKs, exact issuer/API audience, required claims and auth_time, a maximum one-hour lifetime/age and 60-second tolerance. Its frozen verified issuer/subject resolves only to a current pre-registered active human; the existing service then reloads IAM and retains owner-scoped iam:Manage, explicit/default Deny, required decision audit, 30/90-day owner caps and atomic credential lifecycle writes.

Configuration/key and operation fields are captured once; raw tokens/SSO claims stay out of fixed errors and management records. Header keys/URLs cannot select trust or trigger network access. Both injected and configured factories reject authentication/dependency failures before management. The new exact production dependency is jose 6.2.12; private signing keys and synthetic tokens are generated only in test memory.

Validation:

  • Behavioral red: node --experimental-strip-types --test test/sso-access-tokens.test.ts test/sso-token-management.test.ts against deny-only typed exports failed 134 of 190 tests for missing valid verification/composition and missing input/config/clock errors (56 expected denials passed). An initial signing-fixture prevalidation problem was corrected before this red run; it is not counted as verifier evidence.
  • Configuration-boundary red: the configured factory tests failed 7 of 89 cases before own-setting validation and sanitized constructor failures (82 existing cases passed).
  • Green: the focused verifier/composition suite passes 200 tests, including real runtime-signed tokens through all migrated PostgreSQL stores, denial/failure paths, mutations, private records, time bounds, and crypto-key-import failure.
  • Focused V8 coverage: both new production modules have 100% line/function coverage; the composition has 100% branch coverage and the verifier 99.11% branch coverage. Existing reused modules retain their broader suites.
  • Final npm run check: 6,393 passed, zero failed, one existing opt-in real PostgreSQL test skipped locally; typecheck/lint/document-link-contract-secret scans and all three pinned OpenRouter integrity checks pass. Both repository CI jobs additionally gate merge, including the disposable real PostgreSQL service.
  • npm audit --omit=dev: zero known production dependency vulnerabilities at verification time. git diff --check passes. Existing migrations and all three OpenRouter pins are byte-identical to the base.

Limits: this is an internal authentication/management composition, not public login or a management HTTP route. The registered issuer must emit auth_time only for actual end-user authentication; this local restriction is not universal human-grant proof. Automatic/network JWKS rotation, introspection/access-token revocation/replay protection, public authentication-error/audit contracts and audited administrator provisioning remain separate. Manual key changes require a rebuilt verifier. Binding/policy reads are separate; later concurrent changes are not transactionally revalidated. Existing proxy/inference/discovery/IAM/limit/usage paths are unchanged; full release issue #116 and unresolved Jev issue #7 remain open.

Plan: 488-sso-token-management. Contracts: sso-token-management, sso-access-tokens.

Assisted-by: Codex

Refs: #488
Assisted-by: Codex
Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@github-actions github-actions Bot added ai-review-requested Review requested from sjungwon03-ai type:feature Product capability labels Oct 11, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the exact published diff at 4803f82; it is byte-identical to the locally validated commit. No blocking findings.

Blast radius: new internal authentication/management factories and one pinned JWT dependency. Existing public proxy handlers, migrations, OpenRouter pins and IAM/audit/usage implementations are unchanged. No existing endpoint/config contract is removed.

Security review: registered bounded public RSA keys and exact issuer/audience are immutable; RS256 signatures, RFC token type, required claims, selected temporal bounds and local auth_time restriction precede identity SQL. Header key URLs/objects cannot change trust. Only current active-human pre-registered bindings derive the actor; ignored caller authority never grants permissions. Existing fresh IAM, explicit/default Deny, required allow/deny audit, stored-owner scope, owner lifetime caps and atomic mutations are reused. Inputs/getters are captured before awaits; fixed errors and persisted events exclude raw access tokens and SSO claims. Runtime-only generated signing fixtures contain no committed private keys/tokens. Production npm audit reported zero known vulnerabilities.

Validation: 200 focused tests pass; final npm run check passes 6,393 tests plus one existing locally skipped opt-in real PostgreSQL test, strict types/lint/docs/secret scan and all three pin checks. Both new modules have 100% line/function coverage; composition branch coverage is 100%, verifier 99.11%. Reviewed success, rejection, dependency/crypto/clock failures, state changes, mutation safety and credential/audit ordering. Key imports cache within bounded local JWKS; each management operation deliberately re-verifies and reloads current binding/IAM state.

Disclosed limits are appropriate for this internal slice: trusted issuer end-user auth_time semantics, manual key rebuilds, no public HTTP authentication/error/audit or audited provisioning, no JWKS network/replay/introspection/access-token revocation, and separate binding/policy reads without transactional revalidation. Release #116 and unresolved #7 remain open.

This review was performed by Codex using the contributor-authorized sjungwon03-ai account; it is not an independent human review. Assisted-by: Codex

@sjungwon03
sjungwon03 merged commit 40cefa2 into main Oct 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-review-requested Review requested from sjungwon03-ai type:feature Product capability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: verify RFC 9068 SSO token management

2 participants