核心统一身份

reits-auth

非原生客户端的统一身份门面;当前 EC2 已运行 S36 Hosted OAuth、PKCE、Redis 会话/授权码与 MySQL 账户,但 OAuth Client/Consent/Grant 治理仍不完整。

GoHS256 kid key ringRedis challenge/code/sessionMySQL accountim-core S2Ssystemd
7生产 Client
12 / 17SSO Gate
0Client DB 行
S36生产版本
0Consent Ledger
1自动工作流
OWNERIdentity Platform
RUNTIMEGo systemd · 127.0.0.1:8095 · Nginx TLS · Redis auth/code/session · MySQL account
IDENTITYroot of non-native application subject, audience, coarse scopes, signing-key selection and Auth session liveness
DELIVERYGitea main@ca769412 is behind production S36; EC2 release sso-public-cfg-20260724T133627Z is active but exact source SHA unknown; MySQL client overlay loads 0 rows after MariaDB JSON CAST error and falls back to seven seeds

CAPABILITIES

负责的能力

  1. 01

    真实 im-core email/phone OTP 与 App QR

  2. 02

    Hosted /oauth/authorize、Authorization Code 与 S256 PKCE

  3. 03

    Redis 120 秒 single-use code 与 rotating session family

  4. 04

    MySQL opaque account subject

  5. 05

    会话列表及 current/single/others revoke

  6. 06

    OIDC discovery、userinfo 与 JWKS endpoint

  7. 07

    issuer/audience/client/origin/profile 边界

  8. 08

    challenge 双维限流与失败锁定

  9. 09

    im-core + Redis readiness

  10. 010

    production-safe boot validation

UI & ROUTES

页面与接口面

auth.reits.tech Hosted OAuth UIauth.reits.tech /v1/* 与 /oauth/*/api/auth/* 和 xt-op 兼容路径D06-P6 OAuth governance control plane

IMPLEMENTATION CONTRACT

运行、数据与跨项目契约

这部分给开发者和 AI 明确真实入口、状态 owner、稳定接口和可观测证据。

01

Entrypoints

  • Hosted /oauth/authorize
  • authorization_code + refresh_token
  • email/phone OTP + QR
  • introspection/userinfo/JWKS/discovery
  • session list/revoke
  • client reload
  • health/readiness/meta
02

Owned data

  • Redis challenge and 120s single-use code
  • Redis rotating session family with max 20
  • MySQL opaque accounts
  • seven seed-fallback OAuth clients
  • HS256 active key ring
  • no durable Consent ledger or Grant lineage
03

Contracts

  • AuthorizationCode
  • PKCE
  • TokenClaims
  • SessionRecord
  • ClientRegistry
  • OIDC Discovery
  • ConsentPolicy target
  • ConsentLedgerEvent target
  • GrantLineage target
04

Telemetry

  • ready/production-safe
  • S36 12/17
  • client source and reload failure
  • OTP/session typed rejection
  • request/trace IDs without raw credentials

SCREEN DEFINITIONS

0 张已绑定 UI 蓝图

该仓没有独立用户界面;它通过 API、SDK、知识或计算契约支持上层产品。

NO STANDALONE UI

验收重点是契约、fixture、consumer test、性能与生产证据。