Skip to main content

AEROSIM-TS-39

Project task

Implement the Nebula Keycloak PKCE session client

A protected Nebula route redirects an unauthenticated user to Keycloak and restores the originally intended route after successful Authorization Code with PKCE sign-in.

AEROSIM-TS-39Canonical ID TASK-0039
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application — Keycloak session client
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Implement Keycloak OIDC discovery and Authorization Code with S256 PKCE for protected Nebula routes, bind state and nonce to one session transaction, preserve an internal intended pathname, process the callback once, renew before expiry, and perform provider logout. Primary files: applications/web/src/auth/oidc-config.ts, applications/web/src/auth/session-client.ts, applications/web/src/auth/ProtectedRoute.tsx, applications/web/src/auth/callback.tsx, applications/web/tests/auth/session-client.test.tsx.

Implementation contract

Implementation artifacts

  • applications/web/src/auth/oidc-config.ts
  • applications/web/src/auth/session-client.ts
  • applications/web/src/auth/ProtectedRoute.tsx
  • applications/web/src/auth/callback.tsx
  • applications/web/tests/auth/session-client.test.tsx

Inputs

  • OidcConfig {issuer,clientId,redirectUri,postLogoutRedirectUri,scopes}
  • Protected-route location and Keycloak authorization response {code,state}

Outputs

  • Redirect URL containing response_type=code, code_challenge_method=S256, state, nonce, and allowed redirect_uri
  • SessionState authenticated with access-token expiry and restored internal intended route

Failure boundaries

  • Reject state/nonce mismatch, reused callback, missing code, discovery issuer mismatch, and callback error; clear the pending transaction.
  • Reject intended routes with an origin, protocol-relative path, or control characters and restore / instead.

Excluded scope

  • AeroSim account registration, password capture, social-provider brokering, Keycloak realm administration, and durable browser token storage are excluded.

Verification steps

  • pnpm --filter @aerosim/web test -- auth/session-client.test.tsx
  • Start at /foundation-status?tab=build, complete a valid callback, then test mismatched state, replay, external intended URL, and expired renewal token.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #22 reviewed head 2fb70c85a33341f8f9acd93f6681460f6d0cf960, exact-head validation task 1821 succeeded, merged as 39e9b71b6c00b5152fa02bc17a17a0ed1372b864; Wave 4 integrated application head e8bfe781d3295d445cbc46b297874f066cac8301 passed publish task 1832 and validate task 1833. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.