Repository navigation
feat: expose reusable SSO human authentication - #491
Conversation
Refs: #490 Assisted-by: Codex Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Reviewed the exact published diff at 265e91e; it is byte-identical to the locally validated commit. No blocking findings.
Blast radius: one reusable internal human authenticator, existing SSO management wiring/error re-exports and their contracts. The JWT profile, public proxy handlers, policy engine, decision/lifecycle persistence, dependency lockfile, migrations and OpenRouter pins are unchanged. Both module paths export identical authentication error constructor references.
Security: bounded primitive token validation precedes verifier/SQL; a trusted verifier and current exact active-human binding remain mandatory. Rejected/missing/inactive/service identity denies; thrown/malformed verifier data and failed/malformed/ambiguous binding results expose fixed availability errors without raw claims, token, driver messages or causes. Thrown domain names and extra caller/verified fields confer no authority. Ports and reader claims are captured before awaits, parameters are frozen, and later calls reload current state. The authenticator only supplies identity and does not read policies, mutate credentials, append audit/usage or auto-create accounts. Existing issue/revoke retains validation order, current IAM/Deny, required audit, stored owner scoping and lifetime caps; no extra SQL query or auth cache is introduced.
Validation: 43 meaningful new boundary tests and 243 focused JWT/authentication/management cases pass. Final npm run check passes 6,436 tests plus one existing locally skipped opt-in PostgreSQL test, strict types/lint/docs/links/contracts/secret checks and all three pin checks. New authenticator, reused binding reader and refactored SSO service reach 100% line/branch/function coverage in the focused suite. Runtime-only signed fixtures exercise migrated PostgreSQL mapping/active/kind changes and prove no management/audit/usage mutation.
Limits remain explicit: public HTTP/audit/lifetime-error choices are unanswered and are not selected here. Existing registered-issuer auth_time trust, manual key rebuilds, lack of post-read transactional revalidation, network JWKS/replay/introspection/access-token revocation and audited provisioning remain separate, with release #116/#7 open.
This review was performed by Codex using the contributor-authorized sjungwon03-ai account; it is not an independent human review. Assisted-by: Codex
Closes #490
SSO human authentication is now reusable before a future management HTTP body is consumed. createPostgresSsoHumanAuthenticator captures a trusted verifier and query client, validates bounded token input, verifies identity, resolves its current exact pre-registered active-human binding, and returns only the human principal ID. Authentication rejection and dependency failures retain fixed claim-free errors.
The existing SSO issue/revoke service reuses this boundary while preserving operation validation before authentication, current IAM/Deny, required decision audit, owner lifetime caps and atomic credential lifecycle writes. The two authentication error constructors move to the identity module and remain re-exported from the gateway module with identical constructor references. No configuration, migration, dependency, proxy/API/provider/usage or OpenRouter pin changes occur.
Validation:
Limits: this is an internal authentication prerequisite, not a public management HTTP route or authentication-audit contract. The contributor's HTTP contract, anonymous audit surface and public lifetime-error decisions remain unanswered and separate; this issue does not silently select them. Registered issuer auth_time end-user semantics, manual key rebuilds, separate binding/policy reads without transaction revalidation, missing network JWKS/replay/introspection/access-token revocation and audited provisioning remain as previously disclosed. Authentication itself adds no policy lookup, credential/audit/lifecycle/usage mutation or automatic account creation. Full release #116 and unresolved #7 remain open.
Plan: 490-sso-human-authentication. Contracts: sso-human-authentication, sso-token-management.
Assisted-by: Codex