D06-P1 · CROSS-REPOSITORY CONTRACT CONTROL PLANE
把认证碎片变成可以多人并行开发的控制面
这张工作台从四个最新 main 分支反推真实契约:Identity 管客户端与密钥,Security 审 Redirect 与重放,Consumer 迁移 BFF,QA 用同一套状态和失败码验收。当前只完成仓库内设计与校验;D05 仍是第 5 / 36 刀,D06 没有被激活。
SOURCE-BOUND ARCHITECTURE
先绑定代码事实,再定义未来接口
每个判断都落到 exact revision、文件和 Git blob。P1 重新扫描后把 merchantPortalToken 纳入统计,浏览器凭据操作从 P0 的 16 修正为 19。
reits-auth
f5f96747e689main · dirty 0
- internal/registry/clients.go
Three seeded browser-facing clients use 604800-second access-token TTLs; the registry has allowed origins and audiences but no redirect URI, grant, response, PKCE or post-logout registry.
blob c4745c4961b8 - internal/httpapi/sessions.go
Durable refresh rotation and revocation primitives exist, but no browser authorization-code callback binds them to a relying party.
blob 3e69f04c43cb - docs/unified-account-auto-provision.md
Authorization Code, PKCE, Discovery and JWKS are explicitly absent; HS256 and seven-day token TTL remain documented blockers.
blob 23185e5018d9
miniapp-open-platform
71c16722492fmain · dirty 0
- packages/portal-web/src/auth.tsx
reits.portal.token is read, written and removed in localStorage: three browser credential-storage operations.
blob f6208e38942c - packages/portal-web/src/api.ts
The portal attaches the stored Bearer token to API calls and login returns access_token directly to browser code.
blob 68e409fee451 - services/developer-api/cmd/server/main.go
Login delegates with HTTP 421 and authBaseUrl but provides no one-time browser authorization transaction.
blob 437bc6bfbd69
public-booking-platform
6a38c3df682emain · dirty 0
- apps/web/app.js
matrixOrderToken accounts for thirteen localStorage credential operations and remains a Bearer fallback.
blob cc8f1a5df200 - apps/merchant-portal/app.js
merchantPortalToken adds three get/set/remove browser credential-storage operations.
blob b8d1cf65ef46 - apps/api/server.js
An HttpOnly Secure SameSite=Lax member-session cookie is already a usable BFF migration foundation.
blob e827b220ad8e
opensdk
40d9219d607cmain · dirty 0
- README.md
Only a Go bot Bearer client is published; no browser start, callback, session, logout or step-up package exists.
blob d9dcfce9c1cb
AUTH-C01 · CLIENT REGISTRY
客户端不是一条字符串,而是一组可审计的信任边界
Identity Operator 同时看注册清单与 exact detail。三个客户端全部是提案态;页面上的按钮是目标交互稿,不会对 auth.reits.tech 写入。
open-portal-webOpen Platformopenapi.reits.techS256NOT REGISTEREDbooking-member-webBooking Consumerorder.reits.techS256NOT REGISTEREDbooking-merchant-webBooking Merchantorder.reits.techS256NOT REGISTEREDAUTH-C02 · REDIRECT CHANGE REVIEW
任何 Redirect 变化都像基础设施变更一样审批
Security 不审批通配符或前缀匹配。审查稿同时展示来源证据、规范化后的 exact diff、风险探针和四方职责。
allowedOrigins: ["https://openapi.reits.tech"]origin onlyredirectUris: ["https://openapi.reits.tech/auth/callback"]exactpostLogoutRedirectUris: ["https://openapi.reits.tech/signed-out"]exactpkceMethods: ["S256"]requiredtokenEndpointAuthMethod: "private_key_jwt"BFF onlyAUTH-C03 · SESSION FAMILY INSPECTOR
运维看得到会话链路,但永远看不到令牌值
这是 Security Operations 的调查 UI:只投影 hash、kid、事件和边界状态。示例为目标 fixture,不是生产用户会话。
10:04:12.01310:19:04.78210:33:48.09110:34:02.55110:34:02.568AUTH-C04 · CONSUMER MIGRATION CONTROL
四仓各自交付,但只能按同一套合同合流
迁移板把代码责任、退出条件和 UI/QA 回执放在一条线上。五个阶段全部 WAIT_D05,避免把“文档完成”误报成“功能上线”。
Origin-only clients, HS256, seven-day TTL
Discovery, JWKS, code+PKCE, exact client registry and durable revocation
421 handoff plus reits.portal.token
Open Portal BFF with no browser token read API
Partial cookie plus two localStorage Bearer families
Separate member and merchant BFF sessions and deletion of both fallbacks
Go bot Bearer client only
Typed browser start/session/logout/step-up contract without token getter
EIGHT CONTRACTS · TEN STATES
团队共享协议,不共享隐含假设
八个端点定义浏览器可见范围、成功语义与稳定失败码;十态把开始、回调、会话、轮换、step-up、撤销和拒绝分开。
AUTH-CN01GET/.well-known/openid-configurationIdentity PlatformPUBLIC_METADATAISSUER_METADATA_INVALIDAUTH-CN02GET/.well-known/jwks.jsonIdentity SecurityPUBLIC_KEYS_ONLYJWKS_KEY_NOT_FOUNDAUTH-CN03POST/auth/startConsumer BFFREDIRECT_ONLYRETURN_TO_DENIEDAUTH-CN04GET/oauth2/authorizeIdentity PlatformAUTHORIZATION_UIREDIRECT_URI_MISMATCHAUTH-CN05GET/auth/callbackConsumer BFFCODE_AND_STATE_ONCECALLBACK_TRANSACTION_INVALIDAUTH-CN06GET/auth/sessionConsumer BFFSAFE_SESSION_PROJECTIONSESSION_EXPIREDAUTH-CN07POST/auth/refreshConsumer BFF + IdentityCSRF_BOUND_COOKIE_ONLYREFRESH_REUSE_DETECTEDAUTH-CN08POST/auth/logoutConsumer BFF + IdentityCSRF_BOUND_COOKIE_ONLYLOGOUT_PROPAGATION_FAILEDCREATED
BFF persists a short-lived one-time transaction; no token exists.
REDIRECTED
Browser carries only authorization request parameters.
AUTHENTICATED
Identity completes primary authentication and consent.
CODE_ISSUED
Identity issues a single-use code bound to client, redirect and challenge.
CALLBACK_VERIFIED
BFF consumes state, nonce and code exactly once.
SESSION_ESTABLISHED
Host-only Secure HttpOnly SameSite=Lax cookie is set.
REFRESH_ROTATED
Server-side refresh family advances and prior handle is burned.
STEP_UP_REQUIRED
Session remains bounded while a single sensitive action requests higher assurance.
REVOKED
Cookie, refresh family and resource access are invalidated.
DENIED
Any mismatch terminates the transaction without a fallback Bearer path.
FAIL-CLOSED QA
十二个稳定错误码,二十四个敌对场景
协议实现必须返回稳定、无敏感值的错误类型;任何前缀匹配、重放、跨客户端交换、Cookie 冲突或浏览器令牌回退都直接拒绝。
01UNREGISTERED_CLIENT02INVALID_ORIGIN03REDIRECT_URI_MISMATCH04PKCE_REQUIRED05PKCE_VERIFIER_MISMATCH06STATE_MISMATCH07NONCE_REPLAY08CODE_REPLAY09SESSION_EXPIRED10REFRESH_REUSE_DETECTED11CSRF_INVALID12STEP_UP_REQUIRED四个控制台、三个客户端、八份接口契约和二十四个敌对场景已经拼齐
D06-P1 completes a source-bound control-plane design, contract registry and fail-closed verifier only. It does not register clients, issue credentials, modify consumer repositories, mutate AWS/IAM, advance the program ledger or activate D06.