security(auth): migrate public frontend off direct grants - #1120
seonghobae wants to merge 146 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Move backend integration actors to their distinct confidential clients and disable direct grants on the browser client in the same causal change. Browser acceptance remains a separate required gate.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head review at 82723adb2d1fded5f3ba741ac957d3dd5bdd8891: the broad "select_rs256_signing_key" in source assertions introduced by predecessor 0808b081... were a valid evidence-quality defect because a comment or inert string could satisfy the contract without either actor importing the canonical JWKS selector. RED cbbc66863a4d1a28043aed03091529a3eb6b6607 pins a comment-only false positive. The causal fix parses both Python actors with ast and requires an actual ImportFrom lineageweave.oidc_jwks binding for select_rs256_signing_key; the mutation specimen is rejected. Production auth code is unchanged. Hosted Tests 35664877237 is Draft-policy skipped, so no exact-head GREEN or approval is inferred.
Exact-head authority — 2026-09-22 KST
This Draft remains the auth-hardening / public-client ROPC retirement lane.
0dd0fd9a74165a63a081d1435123a79be6feefca73ab7ea24517bfcb1edfc83676f9fb56ea524bc072341358f7edf01360a5da69b01fe87684b8076bc49aff397736db601fd1d2cb428c8006d0090d26The production auth boundary remains unchanged: confidential viewer/admin machine actors use Client Credentials; the public frontend has direct grants disabled and uses Authorization Code + S256 PKCE; OIDC token verification remains RS256/JWKS based. The AST-backed shared-selector import contract at
82723adb...remains the latest causal source/test repair in this lane.Parent #1118 moved only to adopt #899's source-neutral ancestry. Ordinary two-parent/non-force convergence
73ab7ea...adopts current #1118 while preserving this branch's auth delta. Fresh compare has exact merge-base0dd0fd9a...,behind_by=0.Both direct children were immediately converged without rewrite: #1117 fresh compare from this head is
behind_by=0and still owns only README/auth-doc contract; #1124 isbehind_by=0and still owns the same 13 ADR/Storybook/frontend paths. No child delta was copied into the parent and no predecessor receipt transfers.Canonical PostgreSQL-authoritative localization remains owned by Draft #929; this auth lane does not manufacture another translation ledger.
Keep Draft until #1118 is promotable, one unchanged exact head has applicable hosted repository/security/static-analysis GREEN and qualifying independent review, #1124 reacquires browser/frontend/Storybook evidence, and the canonical eight-locale ledger/ACL path is promotable.
No self-approval, Admin bypass, force push, destructive rebase, gate weakening, blind rerun, new no-op wake commit, stale-receipt transfer, protected-main merge, or release is claimed.