OIDC + refresh + soft-logout recovery #76

Closed
opened 2026-08-11 13:37:05 +02:00 by thecrealm · 2 comments
Owner

M4 exit criterion 2: OIDC login, token refresh, and soft-logout recovery per §10.2.3. Acceptance: the §10.2.3 flows pass against a real IdP-enabled homeserver (or the testkit mock where the spec allows), refresh races don't drop requests (NetworkPolicy engine still mediates every outbound request, CR-4), soft-logout recovers without losing store state.

M4 exit criterion 2: OIDC login, token refresh, and soft-logout recovery per §10.2.3. Acceptance: the §10.2.3 flows pass against a real IdP-enabled homeserver (or the testkit mock where the spec allows), refresh races don't drop requests (NetworkPolicy engine still mediates every outbound request, CR-4), soft-logout recovers without losing store state.
thecrealm added
now
and removed
next
labels 2026-08-11 15:32:29 +02:00
Author
Owner

Part 1 landed (24f29b4, D43): OidcAuthProvider (PKCE S256, dynamic registration + static override, URL-out/redirect-in seam), TokenManager single-flight refresh (proactive near expiry + reactive once per failed token; in-flight requests wait), observable session auth states with the MatrixApiClient gate (outbound parks in non-active states, re-auth bypasses), reauthenticate() resuming in place (CR-9-guarded, sync loop restart, no re-sync), terminal logout() via the new /v3/logout endpoint, mock OAuth server + AuthLifecycleTest (5 legs). Remaining part 2 before the roadmap tick: §9 key-material clearing on hard logout — CryptoStore.wipe(principal) through the port, conformance kits, sqlite + in-memory implementations, wired into logout(). MAS real-world leg stays #79.

Part 1 landed (24f29b4, D43): OidcAuthProvider (PKCE S256, dynamic registration + static override, URL-out/redirect-in seam), TokenManager single-flight refresh (proactive near expiry + reactive once per failed token; in-flight requests wait), observable session auth states with the MatrixApiClient gate (outbound parks in non-active states, re-auth bypasses), reauthenticate() resuming in place (CR-9-guarded, sync loop restart, no re-sync), terminal logout() via the new /v3/logout endpoint, mock OAuth server + AuthLifecycleTest (5 legs). Remaining part 2 before the roadmap tick: §9 key-material clearing on hard logout — CryptoStore.wipe(principal) through the port, conformance kits, sqlite + in-memory implementations, wired into logout(). MAS real-world leg stays #79.
Author
Owner

Done across 24f29b4 (part 1: OidcAuthProvider, TokenManager single-flight refresh, session auth states + gate, reauthenticate, mock OAuth + AuthLifecycleTest) and 1bf05b6 (part 2: CryptoStore.wipe + IdentityStore.remove on hard logout, kit-covered); CI-verified builds #220/#221; roadmap ticked in 19793b5. MAS real-world leg stays #79.

Done across 24f29b4 (part 1: OidcAuthProvider, TokenManager single-flight refresh, session auth states + gate, reauthenticate, mock OAuth + AuthLifecycleTest) and 1bf05b6 (part 2: CryptoStore.wipe + IdentityStore.remove on hard logout, kit-covered); CI-verified builds #220/#221; roadmap ticked in 19793b5. MAS real-world leg stays #79.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
thecrealm/katrix#76
No description provided.