D06-P0 · SOURCE-BOUND PRE-ADMISSION
先把浏览器认证的真实断点画清,再允许 D06 开工
这不是一张想象中的登录页。四个仓库已经同步到最新 main;421、localStorage Bearer、部分 HttpOnly Cookie、缺失的 PKCE/JWKS 和不存在的 Browser SDK 都绑定到 exact revision。仓库入场包已完成,但 D05 仍为 0/11,D06 不得激活。
EXACT SOURCE SNAPSHOT
四个仓库都用当前代码说话
4 个仓库已 fetch,工作树均为干净 main。每条判断都绑定 exact revision、文件与 Git blob;后续代码变化必须重新采样。
reits-auth
ca7694128287main · dirty 0
- docs/unified-account-auto-provision.md
The repository explicitly records missing authorization-code, PKCE, Discovery and JWKS plus HS256, long TTL and non-durable challenge blockers.
blob 23185e5018d9
miniapp-open-platform
41d67048b745main · dirty 0
- services/developer-api/cmd/server/main.go
The login routes return HTTP 421 with authBaseUrl but no browser authorization handshake.
blob 933c0815bfdf - packages/portal-web/src/auth.tsx
The portal reads, writes and removes reits.portal.token in localStorage.
blob f6208e38942c - packages/portal-web/src/pages/LoginPage.tsx
The current developer login page directly requests and confirms an email challenge, then stores access_token in browser state.
blob 87ce6750007b
public-booking-platform
6a38c3df682emain · dirty 0
- apps/api/server.js
A SameSite=Lax HttpOnly Secure member-session cookie exists and is a reusable BFF migration foundation.
blob e827b220ad8e - apps/web/console.js
The merchant console still treats matrixOrderToken localStorage Bearer as an authentication fallback.
blob d339d86e6444
opensdk
40d9219d607cmain · dirty 0
- README.md
The published SDK is a Go bot Bearer client; no browser authorization or BFF session package exists.
blob d9dcfce9c1cb
CURRENT CODE X-RAY
现在能复用什么,危险又在哪里
已有会话轮换、421 委派与 HttpOnly Cookie 是基础,不是完成态。任何跨站 redirect、token custody 或九态测试缺失都会继续红门。
Durable session and refresh rotation primitives
OBSERVED_NOT_BROWSER_BOUNDExplicit 421 delegation to auth.reits.tech
OBSERVED_DEAD_END_HANDOFFHttpOnly SameSite member cookie
OBSERVED_PARTIAL_BFFAUTH-01CRITICALHTTP 421 is a dead-end delegation
- REPOSITORY
- miniapp-open-platform
- OBSERVED
- 421 + authBaseUrl only
- TARGET
- BFF start endpoint creates PKCE, state and nonce then returns an exact redirect
AUTH-02CRITICALLong-lived browser Bearer storage remains
- REPOSITORY
- miniapp-open-platform + public-booking-platform
- OBSERVED
- 3 portal token storage operations + 13 matrixOrderToken operations
- TARGET
- No long-lived access or refresh token in localStorage, sessionStorage, URL, DOM or postMessage
AUTH-03CRITICALStandard browser authorization endpoints are absent
- REPOSITORY
- reits-auth
- OBSERVED
- No authorization-code, PKCE, Discovery or JWKS
- TARGET
- Authorization Code + S256 PKCE + issuer discovery + ES256 JWKS
AUTH-04HIGHConsumer BFF behavior is inconsistent
- REPOSITORY
- public-booking-platform + miniapp-open-platform
- OBSERVED
- Booking has a partial HttpOnly cookie; Open Portal keeps a browser Bearer
- TARGET
- One host-only encrypted session family with refresh rotation and server-side token custody
AUTH-05HIGHBrowser SDK package does not exist
- REPOSITORY
- opensdk
- OBSERVED
- Go bot SDK only
- TARGET
- Typed browser start/callback/session/logout/step-up package with no token read API
THREE REAL TARGET SURFACES
不是通用登录卡,而是三个不同责任阶段
S01 只开始授权,S02 只建立 BFF 会话,S03 处理过期、撤销和 step-up。三个页面都不接触 access token 或 refresh token。
使用你的 REITs 账号继续
开放平台将读取基础身份和你有权访问的应用。认证由 auth.reits.tech 完成,本页不会接收令牌。
- Relying party
- Open Portal Web
- Requested
- openid · profile · apps:read
- Return
- https://open.reits.tech/auth/callback
正在建立你的浏览器会话
授权码只发送到 BFF。浏览器只会收到 Host-only、HttpOnly 的会话 Cookie。
- 01State + issuer verifiedExact transaction matchedDONE
- 02Code exchanged server-sideS256 verifier remains in BFF custodyDONE
- 03Session cookie pendingSecure · HttpOnly · SameSite=LaxWORKING
再次确认身份
你正在为 Mini App 发布请求 step-up。验证只提升这一次操作,不会扩大其他会话权限。
- Current session
- Active · expires in 23 min
- Required assurance
- MFA · one action
- After verification
- Return to release review
AUTHORIZATION SEQUENCE
令牌只在 Identity 与 BFF 之间流动
浏览器只持有一次性 code/state/nonce 交换和 Host-only Cookie;资源调用、刷新与撤销都在服务端完成。
POST /auth/start
Bind issuer, client, exact origin, returnTo, S256 challenge, state and nonce; persist only a short-lived server transaction.
GET /oauth2/authorize
Authenticate and consent against registered client, redirect and policy; never return tokens through the browser.
GET /auth/callback
Verify state, issuer and one-time code; exchange with verifier from server custody.
GET /auth/session
Issue a host-only HttpOnly Secure SameSite cookie and expose only subject-safe session metadata.
same-origin /api/*
Attach bounded access server-side and enforce subject, tenant, audience, scope and object authorization.
POST /auth/refresh
Rotate refresh material once, detect replay and revoke the session family on reuse.
POST /auth/logout
Require CSRF, revoke server session, clear cookie and make all consumers deny the old session.
NINE REAL STATES
九态必须改变页面责任区,不允许盖一张万能状态卡
三张页面共需 27 份独立状态回执;当前生产回执 0。
Show verified account, exact relying party, requested scopes and safe continuation.
Replace form controls with a non-repeatable transaction progress view and disable duplicate submission.
Explain that no active session or eligible account exists and offer a source-safe start action.
Preserve verified identity while isolating a failed optional profile, consent or device region.
Discard the authorization transaction and offer a fresh start without replaying code or state.
Stop callback polling, retain no secret material and explain that sign-in cannot complete offline.
Hide protected content, show policy owner and deny return-to escalation or scope broadening.
Display step-up reason, relying party, exact action and bounded confirmation window.
Show session established or revoked with a single safe destination and no credential values.
TEN ADMISSION GATES
0 / 10,全部保持红门
仓库蓝图完成不等于 D06 已开始。A01 首先验证 D05 和账本,A02–A10 才验证认证协议、BFF、存储、撤销、step-up 与 UI QA。
D06-A01DENIEDD05 accepted and ledger CAS completed
D05 0/11; ledger 4/36
D06-A02DENIEDAuthorization Code + S256 PKCE
Absent
D06-A03DENIEDDiscovery + ES256 JWKS
Absent; HS256 remains
D06-A04DENIEDExact client, origin and redirect registration
No source-bound browser client registry
D06-A05DENIEDHost-only BFF session and refresh custody
Partial booking cookie only
D06-A06DENIEDState, nonce, CSRF and replay rejection
No cross-repository browser flow receipt
D06-A07DENIEDZero long-lived browser Bearer storage
16 token storage operations
D06-A08DENIEDRefresh rotation, logout and revocation propagation
Backend primitives exist; browser journey unqualified
D06-A09DENIEDStep-up and return-to policy
No browser contract
D06-A10DENIEDThree surfaces × nine real states QA
Target UI package only; production receipts 0/27
MIGRATION LANES + ADVERSARIAL QA
四仓分工清楚,十二类失败先写进验收
每个仓库只承担自己的信任边界;跨仓成功必须由同一份 source-bound admission receipt 聚合。
reits-auth
WAIT_D05OIDC-compatible authorize/token/discovery/JWKS, browser client registry and bounded step-up policy
miniapp-open-platform
WAIT_D05Replace 421 dead end and localStorage Bearer with start/callback/session/logout BFF routes
public-booking-platform
WAIT_D05Remove matrixOrderToken fallback and bind existing HttpOnly cookie to reits-auth session rotation
opensdk
WAIT_D05Add a browser/BFF package that exposes flow states but never access or refresh token values
目标 UI、协议路径、十道入场门和签名验证器已经拼齐
D06-P0 is a source-bound pre-admission package, not D06 activation or acceptance. It records the exact current code and defines three realistic target surfaces, nine real states, ten admission gates and twelve negative tests. Until D05 has 11/11 gates, four final owners and an external ledger CAS, D06 remains blocked; the first executable program task remains D05-T02.