D06-P0 · SOURCE-BOUND PRE-ADMISSION

先把浏览器认证的真实断点画清,再允许 D06 开工

这不是一张想象中的登录页。四个仓库已经同步到最新 main;421、localStorage Bearer、部分 HttpOnly Cookie、缺失的 PKCE/JWKS 和不存在的 Browser SDK 都绑定到 exact revision。仓库入场包已完成,但 D05 仍为 0/11,D06 不得激活。

PROGRAM LEDGER4 / 36D05 active · 32 including current
REPOSITORY PACKAGED06-P0source inventory · UI · contract · verifier
D06 ACTIVATIONDENIEDD05 acceptance + ledger CAS required

EXACT SOURCE SNAPSHOT

四个仓库都用当前代码说话

4 个仓库已 fetch,工作树均为干净 main。每条判断都绑定 exact revision、文件与 Git blob;后续代码变化必须重新采样。

REPOSITORY

reits-auth

FETCHED
ca7694128287

main · dirty 0

  • docs/unified-account-auto-provision.md

    The repository explicitly records missing authorization-code, PKCE, Discovery and JWKS plus HS256, long TTL and non-durable challenge blockers.

    blob 23185e5018d9
REPOSITORY

miniapp-open-platform

FETCHED
41d67048b745

main · dirty 0

  • services/developer-api/cmd/server/main.go

    The login routes return HTTP 421 with authBaseUrl but no browser authorization handshake.

    blob 933c0815bfdf
  • packages/portal-web/src/auth.tsx

    The portal reads, writes and removes reits.portal.token in localStorage.

    blob f6208e38942c
  • packages/portal-web/src/pages/LoginPage.tsx

    The current developer login page directly requests and confirms an email challenge, then stores access_token in browser state.

    blob 87ce6750007b
REPOSITORY

public-booking-platform

FETCHED
6a38c3df682e

main · dirty 0

  • apps/api/server.js

    A SameSite=Lax HttpOnly Secure member-session cookie exists and is a reusable BFF migration foundation.

    blob e827b220ad8e
  • apps/web/console.js

    The merchant console still treats matrixOrderToken localStorage Bearer as an authentication fallback.

    blob d339d86e6444
REPOSITORY

opensdk

FETCHED
40d9219d607c

main · dirty 0

  • README.md

    The published SDK is a Go bot Bearer client; no browser authorization or BFF session package exists.

    blob d9dcfce9c1cb

CURRENT CODE X-RAY

现在能复用什么,危险又在哪里

已有会话轮换、421 委派与 HttpOnly Cookie 是基础,不是完成态。任何跨站 redirect、token custody 或九态测试缺失都会继续红门。

FOUNDATION-01 · reits-auth

Durable session and refresh rotation primitives

OBSERVED_NOT_BROWSER_BOUND
FOUNDATION-02 · miniapp-open-platform

Explicit 421 delegation to auth.reits.tech

OBSERVED_DEAD_END_HANDOFF
FOUNDATION-03 · public-booking-platform

HttpOnly SameSite member cookie

OBSERVED_PARTIAL_BFF
AUTH-01CRITICAL

HTTP 421 is a dead-end delegation

REPOSITORY
miniapp-open-platform
OBSERVED
421 + authBaseUrl only
TARGET
BFF start endpoint creates PKCE, state and nonce then returns an exact redirect
BLOCKED
AUTH-02CRITICAL

Long-lived browser Bearer storage remains

REPOSITORY
miniapp-open-platform + public-booking-platform
OBSERVED
3 portal token storage operations + 13 matrixOrderToken operations
TARGET
No long-lived access or refresh token in localStorage, sessionStorage, URL, DOM or postMessage
BLOCKED
AUTH-03CRITICAL

Standard browser authorization endpoints are absent

REPOSITORY
reits-auth
OBSERVED
No authorization-code, PKCE, Discovery or JWKS
TARGET
Authorization Code + S256 PKCE + issuer discovery + ES256 JWKS
BLOCKED
AUTH-04HIGH

Consumer BFF behavior is inconsistent

REPOSITORY
public-booking-platform + miniapp-open-platform
OBSERVED
Booking has a partial HttpOnly cookie; Open Portal keeps a browser Bearer
TARGET
One host-only encrypted session family with refresh rotation and server-side token custody
BLOCKED
AUTH-05HIGH

Browser SDK package does not exist

REPOSITORY
opensdk
OBSERVED
Go bot SDK only
TARGET
Typed browser start/callback/session/logout/step-up package with no token read API
BLOCKED

THREE REAL TARGET SURFACES

不是通用登录卡,而是三个不同责任阶段

S01 只开始授权,S02 只建立 BFF 会话,S03 处理过期、撤销和 step-up。三个页面都不接触 access token 或 refresh token。

AUTH-S01OPEN PORTAL · SIGN-IN HANDOFFREADY
R
REITs Open Platformdeveloper.reits.tech verified
return /apps
CONTINUE TO REITS AUTH

使用你的 REITs 账号继续

开放平台将读取基础身份和你有权访问的应用。认证由 auth.reits.tech 完成,本页不会接收令牌。

Relying party
Open Portal Web
Requested
openid · profile · apps:read
Return
https://open.reits.tech/auth/callback
Current: email OTP + localStorageTarget: BFF /auth/start
AUTH-S02CALLBACK · SESSION ESTABLISHMENTLOADING
↗
Returning to Open PortalOne-time transaction · do not refresh
state bound
SECURE CALLBACK

正在建立你的浏览器会话

授权码只发送到 BFF。浏览器只会收到 Host-only、HttpOnly 的会话 Cookie。

  1. 01
    State + issuer verifiedExact transaction matched
    DONE
  2. 02
    Code exchanged server-sideS256 verifier remains in BFF custody
    DONE
  3. 03
    Session cookie pendingSecure · HttpOnly · SameSite=Lax
    WORKING
Current: 421 + authBaseUrlTarget: one-time callback transaction
AUTH-S03SESSION · STEP-UP RECOVERYCONFIRM
SECURITY CHECK

再次确认身份

4:42

你正在为 Mini App 发布请求 step-up。验证只提升这一次操作,不会扩大其他会话权限。

!
Publish candidate app_12999Open Portal · Singapore · Chrome on macOS
Current session
Active · expires in 23 min
Required assurance
MFA · one action
After verification
Return to release review
Current: cookie + Bearer fallbackTarget: session-safe recovery

AUTHORIZATION SEQUENCE

令牌只在 Identity 与 BFF 之间流动

浏览器只持有一次性 code/state/nonce 交换和 Host-only Cookie;资源调用、刷新与撤销都在服务端完成。

01
START · Consumer BFF

POST /auth/start

Bind issuer, client, exact origin, returnTo, S256 challenge, state and nonce; persist only a short-lived server transaction.

02
AUTHORIZE · reits-auth

GET /oauth2/authorize

Authenticate and consent against registered client, redirect and policy; never return tokens through the browser.

03
CALLBACK · Consumer BFF

GET /auth/callback

Verify state, issuer and one-time code; exchange with verifier from server custody.

04
SESSION · Consumer BFF

GET /auth/session

Issue a host-only HttpOnly Secure SameSite cookie and expose only subject-safe session metadata.

05
RESOURCE · Resource BFF

same-origin /api/*

Attach bounded access server-side and enforce subject, tenant, audience, scope and object authorization.

06
REFRESH · Consumer BFF

POST /auth/refresh

Rotate refresh material once, detect replay and revoke the session family on reuse.

07
LOGOUT · Consumer BFF + reits-auth

POST /auth/logout

Require CSRF, revoke server session, clear cookie and make all consumers deny the old session.

NINE REAL STATES

九态必须改变页面责任区,不允许盖一张万能状态卡

三张页面共需 27 份独立状态回执;当前生产回执 0。

01READY

Show verified account, exact relying party, requested scopes and safe continuation.

AUTH-S01 · S02 · S03
02LOADING

Replace form controls with a non-repeatable transaction progress view and disable duplicate submission.

AUTH-S01 · S02 · S03
03EMPTY

Explain that no active session or eligible account exists and offer a source-safe start action.

AUTH-S01 · S02 · S03
04PARTIAL_ERROR

Preserve verified identity while isolating a failed optional profile, consent or device region.

AUTH-S01 · S02 · S03
05ERROR

Discard the authorization transaction and offer a fresh start without replaying code or state.

AUTH-S01 · S02 · S03
06OFFLINE

Stop callback polling, retain no secret material and explain that sign-in cannot complete offline.

AUTH-S01 · S02 · S03
07FORBIDDEN

Hide protected content, show policy owner and deny return-to escalation or scope broadening.

AUTH-S01 · S02 · S03
08CONFIRM

Display step-up reason, relying party, exact action and bounded confirmation window.

AUTH-S01 · S02 · S03
09SUCCESS

Show session established or revoked with a single safe destination and no credential values.

AUTH-S01 · S02 · S03

TEN ADMISSION GATES

0 / 10,全部保持红门

仓库蓝图完成不等于 D06 已开始。A01 首先验证 D05 和账本,A02–A10 才验证认证协议、BFF、存储、撤销、step-up 与 UI QA。

D06-A01DENIED

D05 accepted and ledger CAS completed

D05 0/11; ledger 4/36

Program Ledger Authority
D06-A02DENIED

Authorization Code + S256 PKCE

Absent

Identity Platform
D06-A03DENIED

Discovery + ES256 JWKS

Absent; HS256 remains

Identity Security
D06-A04DENIED

Exact client, origin and redirect registration

No source-bound browser client registry

Identity Platform + Consumer Owners
D06-A05DENIED

Host-only BFF session and refresh custody

Partial booking cookie only

Consumer Owners
D06-A06DENIED

State, nonce, CSRF and replay rejection

No cross-repository browser flow receipt

Security Owner
D06-A07DENIED

Zero long-lived browser Bearer storage

16 token storage operations

Consumer Owners
D06-A08DENIED

Refresh rotation, logout and revocation propagation

Backend primitives exist; browser journey unqualified

Identity + Resource Owners
D06-A09DENIED

Step-up and return-to policy

No browser contract

Identity Security + Product
D06-A10DENIED

Three surfaces × nine real states QA

Target UI package only; production receipts 0/27

Design + QA

MIGRATION LANES + ADVERSARIAL QA

四仓分工清楚,十二类失败先写进验收

每个仓库只承担自己的信任边界;跨仓成功必须由同一份 source-bound admission receipt 聚合。

reits-auth

WAIT_D05
Identity Platform

OIDC-compatible authorize/token/discovery/JWKS, browser client registry and bounded step-up policy

miniapp-open-platform

WAIT_D05
Developer Platform

Replace 421 dead end and localStorage Bearer with start/callback/session/logout BFF routes

public-booking-platform

WAIT_D05
Booking Platform

Remove matrixOrderToken fallback and bind existing HttpOnly cookie to reits-auth session rotation

opensdk

WAIT_D05
SDK Platform

Add a browser/BFF package that exposes flow states but never access or refresh token values

01unregistered_client02origin_mismatch03redirect_uri_mismatch04missing_pkce05pkce_downgrade_plain06state_mismatch07nonce_replay08authorization_code_replay09csrf_logout10refresh_token_reuse11expired_step_up12browser_token_leak
D06-P0 REPOSITORY COMPLETE

目标 UI、协议路径、十道入场门和签名验证器已经拼齐

D06-P0 is a source-bound pre-admission package, not D06 activation or acceptance. It records the exact current code and defines three realistic target surfaces, nine real states, ten admission gates and twelve negative tests. Until D05 has 11/11 gates, four final owners and an external ledger CAS, D06 remains blocked; the first executable program task remains D05-T02.