Skip to content

feat: expose SSO proxy-token management HTTP API - #493

Merged
sjungwon03 merged 2 commits into
mainfrom
feat/492-sso-management-http
Oct 11, 2026
Merged

sjungwon03 merged 2 commits into
mainfrom
feat/492-sso-management-http

Conversation

@sjungwon03

@sjungwon03 sjungwon03 commented Oct 11, 2026 •

Copy link
Copy Markdown
Member

Closes #492

Administrators now have separate SSO-authenticated Fetch and unbound Node factories for POST /management/v1/proxy-tokens (201 credentialId/token) and POST /management/v1/proxy-tokens/revoke (200 revoked). A configured factory verifies the selected local-key RFC 9068 access token and current pre-registered active-human binding before consuming the body, derives the actor internally and reuses current IAM/Deny, owner-kind caps, required decision audit and atomic credential lifecycle audit.

Authentication denials and outages append management-specific anonymous gateway metadata containing only server request ID, timestamp and issue/revoke operation; required append failure returns 503. Every response, including Node adapter fallback, uses no-store and fixed safe errors. After IAM Allow/audit, past/equal-now or over human30/service90-day expiry now throws a fresh safe typed lifetime error mapped to 400; dependency/clock/mutation failures remain 503. Unknown revoke denies; an already-revoked credential still requires current owner IAM before revoked:false.

The parser accepts exact own fields, bounded well-formed IDs, safe-integer epoch-millisecond expiry, application/json and at most 16 KiB of fatal-decoded streamed UTF-8. It rejects actor/cap/request-ID overrides and queries after authentication, stops on pre-dispatch cancellation and projects only expected success fields. The generic Node bridge gains an optional fallback responder; both proxy error formats retain their previous default 500 behavior. No migrations, dependencies, provider/API, usage/limits or source-pin changes occur.

Validation:

  • Behavioral red: lifetime boundary tests initially failed 6 expected-expiry cases because the previous service returned TokenManagementUnavailable; 12 existing success/denial/dependency checks passed. Gateway audit tests initially failed 4 management anonymous append cases because the old projector rejected their kinds; 8 existing/invalid-event checks passed. The initial public HTTP/configured tests separately failed on the absent module/factories (scaffold evidence, not behavioral regression evidence).
  • Green: the extended focused coordinator/audit/SSO/socket regression suite passed 277 tests before the additional boundary cases; final management HTTP/configuration/default-proxy socket tests pass 160 cases. Tests include runtime-generated signed JWTs, migrated PGlite stores, exact caps, fresh bindings/activity/kinds/current IAM, denial and required audit precedence, lifecycle rollback, safe SQL/clock failures, streamed size/UTF-8/cancellation cleanup, trusted-port capture, body forgery and private error projection. The final injected handler suite has 122 passing cases.
  • New HTTP handler and configured composition reach 100% line/branch/function coverage. Body parsing retains the decoded result until reader cleanup completes; tests remain green through this refactor. The guarded PostgreSQL coordinator also reaches 100% in the focused regression suite.
  • Final npm run check passes 6,612 tests, zero failed, with one existing opt-in real PostgreSQL test skipped locally; strict types, lint, planning/link/contract/secret checks and all three OpenRouter schema-pin integrity checks pass. Both exact-head repository check jobs additionally gate merge, including real disposable PostgreSQL.
  • Exact published-head review requested a fix for consumed/locked Fetch bodies returning 503. Two regressions reproduced the failure (120 pass, 2 failed); reader acquisition now fails safely as 400 after authentication, with no IAM/mutation or fabricated audit. Both regressions are green (122 pass) with 100% handler line/branch/function coverage. A fresh exact-head review and both CI jobs are required after the correction.
  • git diff --check passes. Documentation updates cover the selected HTTP contract, lifetime error change and prior pending foundation status. Temporary test-fixture table naming, helper defaults and TypeScript/formatting failures were corrected before final validation.

Limits: factories do not activate existing owned proxy runtimes. Deployment must provide trusted issuer/audience/keys, pre-registered human bindings, migrations, request IDs, TLS/routing/listening and DB lifetime. Binding, policy and owner reads are not transactionally revalidated. Lost issuance responses can leave valid unseen tokens; request IDs only correlate, with no automatic retries/deduplication. Required auth_time relies on trusted issuer semantics; audited binding provisioning, network JWKS/replay/introspection/access-token revocation, full release #116 and unresolved #7 remain open.

Plan: 492-sso-management-http. Contracts: sso-management-http, proxy-token-lifetimes.

Assisted-by: Codex

Refs: #492
Assisted-by: Codex
Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@github-actions github-actions Bot added ai-review-requested Review requested from sjungwon03-ai type:feature Product capability labels Oct 11, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex-operated review under the authorized sjungwon03-ai account, not an independent human review. Reviewed the exact published head 306611f. Authentication/IAM/audit privacy and no-store paths otherwise match the selected scope. Requesting one contract correction: consumed/locked Fetch request bodies currently throw at getReader outside the parser catch and return 503, rather than the documented 400 validation response. Added public-boundary regressions reproduce both cases (120 pass, 2 expected failures). Preserve authentication-before-body and no mutation/audit side effects while fixing this. CI remains a merge gate.

Comment thread src/gateway/sso-management-http.ts
Classify consumed or locked Fetch bodies as invalid requests after SSO
authentication, preserving no mutation and safe fixed responses.

Refs: #492
Assisted-by: Codex
Signed-off-by: sjungwon03 <sjungwon03@gmail.com>

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex-operated review under the explicitly authorized sjungwon03-ai account; this is not an independent human review.

Reviewed the exact published final head against issue #492, its English plan and selected contracts, and byte-compared the published diff with the locally checked tree. No blocking findings remain. The earlier consumed/locked Fetch-body correction is implemented after authentication, with no IAM/credential dispatch and a fixed 400; both failing regressions now pass. Fresh review supersedes the initial requested changes.

The handler derives actor identity solely from trusted RFC9068 verification/current active-human binding, captures ports and server IDs, authenticates before bounded UTF8 JSON/query/shape checks, rejects forged authority, and preserves current IAM/Deny, owner caps, required decision audit and atomic credential lifecycle events. Safe typed lifetime propagation preserves denial/dependency priority. Anonymous auth events project only operation with null identity attribution, required append failure wins, and no claims/body/token/error detail is serialized. Success projection, no-store, cancellation cleanup, malformed dependency outputs and consumed/locked streams are covered. Existing proxy Node error formats retain default behavior through both bases. No migrations, dependencies, source pins, inference, limit or usage behavior change.

Validation: final npm run check has 6,612 passes, zero failures and one existing locally skipped opt-in real PostgreSQL case; strict types/lint, planning/link/contract/secret checks and all three pin checks pass. Runtime-generated JWT/migrated PGlite/real Node socket cases cover success, fresh IAM/binding changes, Deny, unknown/repeated revoke, mandatory audit/dependency failures and rollback. HTTP handler and configured composition have 100% line/branch/function coverage; both exact-head repository check jobs, including real disposable PostgreSQL, are additionally verified before this approval.

Remaining deployment/issuer/provisioning work is explicitly documented: separate factories do not activate owned runtimes; issuer auth_time semantics/manual key rebuilds remain required; reads are not transactionally revalidated; lost issuance responses are ambiguous without automatic retry/deduplication. Full #116 and unresolved #7 remain open. These are disclosed scope limits, not silently selected release behavior.

@sjungwon03
sjungwon03 merged commit bf6d8d4 into main Oct 11, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-review-requested Review requested from sjungwon03-ai type:feature Product capability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: expose SSO proxy-token management HTTP API

2 participants