Repository navigation
Conversation
…erver - ConsentPanel and answerUrl move to identity-core, with their 18 tests, story, fixture and translations. Volto's Consent renders the panel. - Aurora's /oauth-consent: the loader describes the request through @oauth-consent as the user; the answer is a navigation back to the authorization endpoint. - Aurora passes the authorization server's endpoints on to the backend (@@oauth-authorize, @@oauth-token, @@oauth-jwks, @@oauth-userinfo, .well-known/openid-configuration), through the virtual-host URL without ++api++. On @@oauth-authorize it sends the session as a bearer token: the backend cannot read Aurora's cookie. No reverse-proxy rule needed. - Plone's require_login challenge is answered with Aurora's /login, keeping came_from; a password sign-in returning to a backend view leaves the app with redirectDocument. - Playwright: a signed-in user agrees, the application gets a code and exchanges it for tokens at Aurora's address, the grant is listed on /applications and withdrawn; a refusal reaches the application as access_denied; a signed-out visitor signs in through Dex first. Refs #132
3 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ninth and last page phase of #132, stacked on #140. Draft: please don't merge. Each phase gets its own PR, built on the previous one, and none is merged until the whole series has been reviewed.
OAuth consent, from the plan. With it, Aurora can be the frontend of a site that is an OpenID Connect provider. Every page a user meets now exists in both add-ons; the control panels stay Volto-only.
The panel moves to core
ConsentPanelandanswerUrlmove toidentity-core, with their 18 tests (core 356 → 374, Volto 612 → 594), story,CONSENT_REQUESTfixture and 8 translated messages. Volto'sConsentkeeps its Redux state and renders the panel insideVoltoIdentityUI.Aurora's
/oauth-consentUnder publicui's layout. The loader describes the request through
@oauth-consentas the user; a signed-out visitor goes to/loginwith the request ascame_from. The answer is not sent from the page. It is a navigation back to the authorization endpoint (answerUrl), as in Volto, because the endpoint answers with a redirect the browser must follow.noindexinmeta.Aurora serves the authorization server's endpoints
This is the part Volto gets from elsewhere.
@@oauth-authorizeand its siblings are backend browser views, not REST services. With Volto, a reverse-proxy rule routes them to the backend (concepts/federation.md, and the demo stack's traefik labels). The backend recognises the user at@@oauth-authorizeby aBearertoken or Volto'sauth_tokencookie. Aurora's session is its own signed cookie, which the backend cannot read, so even behind that rule Aurora users would arrive at the authorize endpoint anonymous.So Aurora passes those requests on itself (
lib/oauth.ts,routes/oauth.ts):@@oauth-authorizeBearer, and nothing the browser sent asAuthorization: a cached Basic credential must not stand in for the user@@oauth-token,@@oauth-jwks,@@oauth-userinfoAuthorization, content type and body.well-known/openid-configurationThe details:
++api++(backendUrl(..., { api: false })), so the backend's answers name Aurora's address.Location,Content-Type,Cache-Control,PragmaandWWW-Authenticateare passed back. NoSet-Cookie, and the browser's cookies are never sent on.Two smaller pieces close the loop:
require_login: a signed-out visitor at the authorize endpoint is sent to Plone's challenge,/acl_users/credentials_cookie_auth/require_login?came_from=…. Aurora answers it with/login?came_from=….redirectDocument: a password sign-in whosecame_fromis a backend view leaves the app with a full page load, since it is not a route the router can navigate to. Unit test seen failing without it.One cost. Aurora's own request handling runs first on every passed-on request, and fetches the site root's content for it. Documented in
concepts/frontends.md.Acceptance tests
oauth-consent.spec.ts. The setup installs the[server]layer through@addons, setsserver_issuerto Aurora's address andserver_consent_urlto/oauth-consent, and registers a confidential client,test-app. The cleanup undoes all three.codeand thestate@@oauth-tokenfor an access token and an ID token/applications, withdrawn through the dialog. This is the full flow phase 8 left for this phaseerror=access_denied/login→ Dex → back to the authorize request → the consent screenAll 14 acceptance tests pass locally, twice in a row. Not run in CI yet.
Checks
lib/oauth, +2require-login, +2login, +1backendUrl)make -C frontend lint,make aurora-lint, both typechecksci-i18n, both harnessespnpm build;make aurora-buildmake docs-build; ValeDocs
concepts/frontends.mdgains "In front of an authorization server", and its "What Aurora does not have yet" is now the control panels alone.concepts/federation.mdnotes that Aurora needs no OAuth routing rule.