Skip to content

security(auth): migrate public frontend off direct grants - #1120

Draft
seonghobae wants to merge 146 commits into
fix/oidc-smoke-declared-jwt-dependencyfrom
fix/eliminate-public-client-ropc-20260918
Draft

seonghobae wants to merge 146 commits into
fix/oidc-smoke-declared-jwt-dependencyfrom
fix/eliminate-public-client-ropc-20260918

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Exact-head authority — 2026-09-22 KST

This Draft remains the auth-hardening / public-client ROPC retirement lane.

The production auth boundary remains unchanged: confidential viewer/admin machine actors use Client Credentials; the public frontend has direct grants disabled and uses Authorization Code + S256 PKCE; OIDC token verification remains RS256/JWKS based. The AST-backed shared-selector import contract at 82723adb... remains the latest causal source/test repair in this lane.

Parent #1118 moved only to adopt #899's source-neutral ancestry. Ordinary two-parent/non-force convergence 73ab7ea... adopts current #1118 while preserving this branch's auth delta. Fresh compare has exact merge-base 0dd0fd9a..., behind_by=0.

Both direct children were immediately converged without rewrite: #1117 fresh compare from this head is behind_by=0 and still owns only README/auth-doc contract; #1124 is behind_by=0 and still owns the same 13 ADR/Storybook/frontend paths. No child delta was copied into the parent and no predecessor receipt transfers.

Canonical PostgreSQL-authoritative localization remains owned by Draft #929; this auth lane does not manufacture another translation ledger.

Keep Draft until #1118 is promotable, one unchanged exact head has applicable hosted repository/security/static-analysis GREEN and qualifying independent review, #1124 reacquires browser/frontend/Storybook evidence, and the canonical eight-locale ledger/ACL path is promotable.

No self-approval, Admin bypass, force push, destructive rebase, gate weakening, blind rerun, new no-op wake commit, stale-receipt transfer, protected-main merge, or release is claimed.

@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review at 82723adb2d1fded5f3ba741ac957d3dd5bdd8891: the broad "select_rs256_signing_key" in source assertions introduced by predecessor 0808b081... were a valid evidence-quality defect because a comment or inert string could satisfy the contract without either actor importing the canonical JWKS selector. RED cbbc66863a4d1a28043aed03091529a3eb6b6607 pins a comment-only false positive. The causal fix parses both Python actors with ast and requires an actual ImportFrom lineageweave.oidc_jwks binding for select_rs256_signing_key; the mutation specimen is rejected. Production auth code is unchanged. Hosted Tests 35664877237 is Draft-policy skipped, so no exact-head GREEN or approval is inferred.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant