OIDC + refresh + soft-logout recovery #76
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
M4 exit criterion 2: OIDC login, token refresh, and soft-logout recovery per §10.2.3. Acceptance: the §10.2.3 flows pass against a real IdP-enabled homeserver (or the testkit mock where the spec allows), refresh races don't drop requests (NetworkPolicy engine still mediates every outbound request, CR-4), soft-logout recovers without losing store state.
Part 1 landed (
24f29b4, D43): OidcAuthProvider (PKCE S256, dynamic registration + static override, URL-out/redirect-in seam), TokenManager single-flight refresh (proactive near expiry + reactive once per failed token; in-flight requests wait), observable session auth states with the MatrixApiClient gate (outbound parks in non-active states, re-auth bypasses), reauthenticate() resuming in place (CR-9-guarded, sync loop restart, no re-sync), terminal logout() via the new /v3/logout endpoint, mock OAuth server + AuthLifecycleTest (5 legs). Remaining part 2 before the roadmap tick: §9 key-material clearing on hard logout — CryptoStore.wipe(principal) through the port, conformance kits, sqlite + in-memory implementations, wired into logout(). MAS real-world leg stays #79.Done across
24f29b4(part 1: OidcAuthProvider, TokenManager single-flight refresh, session auth states + gate, reauthenticate, mock OAuth + AuthLifecycleTest) and1bf05b6(part 2: CryptoStore.wipe + IdentityStore.remove on hard logout, kit-covered); CI-verified builds #220/#221; roadmap ticked in19793b5. MAS real-world leg stays #79.