Skip to content

feat: expose reusable SSO human authentication - #491

Merged
sjungwon03 merged 1 commit into
mainfrom
feat/490-sso-human-authentication
Oct 11, 2026
Merged

sjungwon03 merged 1 commit into
mainfrom
feat/490-sso-human-authentication

Conversation

@sjungwon03

Copy link
Copy Markdown
Member

Closes #490

SSO human authentication is now reusable before a future management HTTP body is consumed. createPostgresSsoHumanAuthenticator captures a trusted verifier and query client, validates bounded token input, verifies identity, resolves its current exact pre-registered active-human binding, and returns only the human principal ID. Authentication rejection and dependency failures retain fixed claim-free errors.

The existing SSO issue/revoke service reuses this boundary while preserving operation validation before authentication, current IAM/Deny, required decision audit, owner lifetime caps and atomic credential lifecycle writes. The two authentication error constructors move to the identity module and remain re-exported from the gateway module with identical constructor references. No configuration, migration, dependency, proxy/API/provider/usage or OpenRouter pin changes occur.

Validation:

  • Behavioral red: node --experimental-strip-types --test test/sso-human-authentication.test.ts against a deny-only typed export failed 31 of 43 tests for missing valid authentication, dependency classification and verifier/binding work; 12 expected denials/alias checks passed. Missing-module failure was separately observed and is not the behavioral evidence.
  • Green: all 43 new boundary tests pass; focused boundary/JWT/management regression suite passes 243 tests. Runtime-generated signed JWTs exercise all migrated PostgreSQL stores and current mapping/kind/active changes. Invalid input/verifier claims, missing/service/inactive/ambiguous/malformed bindings, throws, capture/mutation/privacy and constructor aliases are covered.
  • Focused V8 coverage: the new authenticator and refactored SSO management service have 100% line/branch/function coverage. The existing binding reader also reaches 100% in this suite.
  • Final npm run check passes 6,436 tests, zero failed, with one existing opt-in real PostgreSQL test skipped locally; strict types, lint, planning/link/contract/secret checks and all three OpenRouter pin-integrity checks pass. Both repository CI jobs additionally gate merge, including real disposable PostgreSQL.
  • git diff --check passes; all existing migrations and structural pins remain unchanged. Formatting/import reordering and a restricted test-helper variable-name lint failure were corrected before the final full check.

Limits: this is an internal authentication prerequisite, not a public management HTTP route or authentication-audit contract. The contributor's HTTP contract, anonymous audit surface and public lifetime-error decisions remain unanswered and separate; this issue does not silently select them. Registered issuer auth_time end-user semantics, manual key rebuilds, separate binding/policy reads without transaction revalidation, missing network JWKS/replay/introspection/access-token revocation and audited provisioning remain as previously disclosed. Authentication itself adds no policy lookup, credential/audit/lifecycle/usage mutation or automatic account creation. Full release #116 and unresolved #7 remain open.

Plan: 490-sso-human-authentication. Contracts: sso-human-authentication, sso-token-management.

Assisted-by: Codex

Refs: #490
Assisted-by: Codex
Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@github-actions github-actions Bot added ai-review-requested Review requested from sjungwon03-ai type:feature Product capability labels Oct 11, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the exact published diff at 265e91e; it is byte-identical to the locally validated commit. No blocking findings.

Blast radius: one reusable internal human authenticator, existing SSO management wiring/error re-exports and their contracts. The JWT profile, public proxy handlers, policy engine, decision/lifecycle persistence, dependency lockfile, migrations and OpenRouter pins are unchanged. Both module paths export identical authentication error constructor references.

Security: bounded primitive token validation precedes verifier/SQL; a trusted verifier and current exact active-human binding remain mandatory. Rejected/missing/inactive/service identity denies; thrown/malformed verifier data and failed/malformed/ambiguous binding results expose fixed availability errors without raw claims, token, driver messages or causes. Thrown domain names and extra caller/verified fields confer no authority. Ports and reader claims are captured before awaits, parameters are frozen, and later calls reload current state. The authenticator only supplies identity and does not read policies, mutate credentials, append audit/usage or auto-create accounts. Existing issue/revoke retains validation order, current IAM/Deny, required audit, stored owner scoping and lifetime caps; no extra SQL query or auth cache is introduced.

Validation: 43 meaningful new boundary tests and 243 focused JWT/authentication/management cases pass. Final npm run check passes 6,436 tests plus one existing locally skipped opt-in PostgreSQL test, strict types/lint/docs/links/contracts/secret checks and all three pin checks. New authenticator, reused binding reader and refactored SSO service reach 100% line/branch/function coverage in the focused suite. Runtime-only signed fixtures exercise migrated PostgreSQL mapping/active/kind changes and prove no management/audit/usage mutation.

Limits remain explicit: public HTTP/audit/lifetime-error choices are unanswered and are not selected here. Existing registered-issuer auth_time trust, manual key rebuilds, lack of post-read transactional revalidation, network JWKS/replay/introspection/access-token revocation and audited provisioning remain separate, with release #116/#7 open.

This review was performed by Codex using the contributor-authorized sjungwon03-ai account; it is not an independent human review. Assisted-by: Codex

@sjungwon03
sjungwon03 merged commit d1cc916 into main Oct 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-review-requested Review requested from sjungwon03-ai type:feature Product capability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: expose reusable SSO human authentication

2 participants