Repository navigation
feat: expose SSO proxy-token management HTTP API - #493
Conversation
Refs: #492 Assisted-by: Codex Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Codex-operated review under the authorized sjungwon03-ai account, not an independent human review. Reviewed the exact published head 306611f. Authentication/IAM/audit privacy and no-store paths otherwise match the selected scope. Requesting one contract correction: consumed/locked Fetch request bodies currently throw at getReader outside the parser catch and return 503, rather than the documented 400 validation response. Added public-boundary regressions reproduce both cases (120 pass, 2 expected failures). Preserve authentication-before-body and no mutation/audit side effects while fixing this. CI remains a merge gate.
Classify consumed or locked Fetch bodies as invalid requests after SSO authentication, preserving no mutation and safe fixed responses. Refs: #492 Assisted-by: Codex Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Codex-operated review under the explicitly authorized sjungwon03-ai account; this is not an independent human review.
Reviewed the exact published final head against issue #492, its English plan and selected contracts, and byte-compared the published diff with the locally checked tree. No blocking findings remain. The earlier consumed/locked Fetch-body correction is implemented after authentication, with no IAM/credential dispatch and a fixed 400; both failing regressions now pass. Fresh review supersedes the initial requested changes.
The handler derives actor identity solely from trusted RFC9068 verification/current active-human binding, captures ports and server IDs, authenticates before bounded UTF8 JSON/query/shape checks, rejects forged authority, and preserves current IAM/Deny, owner caps, required decision audit and atomic credential lifecycle events. Safe typed lifetime propagation preserves denial/dependency priority. Anonymous auth events project only operation with null identity attribution, required append failure wins, and no claims/body/token/error detail is serialized. Success projection, no-store, cancellation cleanup, malformed dependency outputs and consumed/locked streams are covered. Existing proxy Node error formats retain default behavior through both bases. No migrations, dependencies, source pins, inference, limit or usage behavior change.
Validation: final npm run check has 6,612 passes, zero failures and one existing locally skipped opt-in real PostgreSQL case; strict types/lint, planning/link/contract/secret checks and all three pin checks pass. Runtime-generated JWT/migrated PGlite/real Node socket cases cover success, fresh IAM/binding changes, Deny, unknown/repeated revoke, mandatory audit/dependency failures and rollback. HTTP handler and configured composition have 100% line/branch/function coverage; both exact-head repository check jobs, including real disposable PostgreSQL, are additionally verified before this approval.
Remaining deployment/issuer/provisioning work is explicitly documented: separate factories do not activate owned runtimes; issuer auth_time semantics/manual key rebuilds remain required; reads are not transactionally revalidated; lost issuance responses are ambiguous without automatic retry/deduplication. Full #116 and unresolved #7 remain open. These are disclosed scope limits, not silently selected release behavior.
Closes #492
Administrators now have separate SSO-authenticated Fetch and unbound Node factories for POST /management/v1/proxy-tokens (201 credentialId/token) and POST /management/v1/proxy-tokens/revoke (200 revoked). A configured factory verifies the selected local-key RFC 9068 access token and current pre-registered active-human binding before consuming the body, derives the actor internally and reuses current IAM/Deny, owner-kind caps, required decision audit and atomic credential lifecycle audit.
Authentication denials and outages append management-specific anonymous gateway metadata containing only server request ID, timestamp and issue/revoke operation; required append failure returns 503. Every response, including Node adapter fallback, uses no-store and fixed safe errors. After IAM Allow/audit, past/equal-now or over human30/service90-day expiry now throws a fresh safe typed lifetime error mapped to 400; dependency/clock/mutation failures remain 503. Unknown revoke denies; an already-revoked credential still requires current owner IAM before revoked:false.
The parser accepts exact own fields, bounded well-formed IDs, safe-integer epoch-millisecond expiry, application/json and at most 16 KiB of fatal-decoded streamed UTF-8. It rejects actor/cap/request-ID overrides and queries after authentication, stops on pre-dispatch cancellation and projects only expected success fields. The generic Node bridge gains an optional fallback responder; both proxy error formats retain their previous default 500 behavior. No migrations, dependencies, provider/API, usage/limits or source-pin changes occur.
Validation:
Limits: factories do not activate existing owned proxy runtimes. Deployment must provide trusted issuer/audience/keys, pre-registered human bindings, migrations, request IDs, TLS/routing/listening and DB lifetime. Binding, policy and owner reads are not transactionally revalidated. Lost issuance responses can leave valid unseen tokens; request IDs only correlate, with no automatic retries/deduplication. Required auth_time relies on trusted issuer semantics; audited binding provisioning, network JWKS/replay/introspection/access-token revocation, full release #116 and unresolved #7 remain open.
Plan: 492-sso-management-http. Contracts: sso-management-http, proxy-token-lifetimes.
Assisted-by: Codex