核心统一身份
reits-auth
非原生客户端的统一身份门面;当前 EC2 已运行 S36 Hosted OAuth、PKCE、Redis 会话/授权码与 MySQL 账户,但 OAuth Client/Consent/Grant 治理仍不完整。
GoHS256 kid key ringRedis challenge/code/sessionMySQL accountim-core S2Ssystemd
7生产 Client
12 / 17SSO Gate
0Client DB 行
S36生产版本
0Consent Ledger
1自动工作流
CAPABILITIES
负责的能力
- 01
真实 im-core email/phone OTP 与 App QR
- 02
Hosted /oauth/authorize、Authorization Code 与 S256 PKCE
- 03
Redis 120 秒 single-use code 与 rotating session family
- 04
MySQL opaque account subject
- 05
会话列表及 current/single/others revoke
- 06
OIDC discovery、userinfo 与 JWKS endpoint
- 07
issuer/audience/client/origin/profile 边界
- 08
challenge 双维限流与失败锁定
- 09
im-core + Redis readiness
- 010
production-safe boot validation
UI & ROUTES
页面与接口面
auth.reits.tech Hosted OAuth UIauth.reits.tech /v1/* 与 /oauth/*/api/auth/* 和 xt-op 兼容路径D06-P6 OAuth governance control planeIMPLEMENTATION CONTRACT
运行、数据与跨项目契约
这部分给开发者和 AI 明确真实入口、状态 owner、稳定接口和可观测证据。
Entrypoints
- Hosted /oauth/authorize
- authorization_code + refresh_token
- email/phone OTP + QR
- introspection/userinfo/JWKS/discovery
- session list/revoke
- client reload
- health/readiness/meta
Owned data
- Redis challenge and 120s single-use code
- Redis rotating session family with max 20
- MySQL opaque accounts
- seven seed-fallback OAuth clients
- HS256 active key ring
- no durable Consent ledger or Grant lineage
Contracts
- AuthorizationCode
- PKCE
- TokenClaims
- SessionRecord
- ClientRegistry
- OIDC Discovery
- ConsentPolicy target
- ConsentLedgerEvent target
- GrantLineage target
Telemetry
- ready/production-safe
- S36 12/17
- client source and reload failure
- OTP/session typed rejection
- request/trace IDs without raw credentials
SCREEN DEFINITIONS
0 张已绑定 UI 蓝图
该仓没有独立用户界面;它通过 API、SDK、知识或计算契约支持上层产品。
NO STANDALONE UI
验收重点是契约、fixture、consumer test、性能与生产证据。