AEROSIM-TS-39
Implement the Nebula Keycloak PKCE session client
A protected Nebula route redirects an unauthenticated user to Keycloak and restores the originally intended route after successful Authorization Code with PKCE sign-in.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-50
- Component
- Web Application — Keycloak session client
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Implement Keycloak OIDC discovery and Authorization Code with S256 PKCE for protected Nebula routes, bind state and nonce to one session transaction, preserve an internal intended pathname, process the callback once, renew before expiry, and perform provider logout. Primary files: applications/web/src/auth/oidc-config.ts, applications/web/src/auth/session-client.ts, applications/web/src/auth/ProtectedRoute.tsx, applications/web/src/auth/callback.tsx, applications/web/tests/auth/session-client.test.tsx.
Implementation contract
Implementation artifacts
- applications/web/src/auth/oidc-config.ts
- applications/web/src/auth/session-client.ts
- applications/web/src/auth/ProtectedRoute.tsx
- applications/web/src/auth/callback.tsx
- applications/web/tests/auth/session-client.test.tsx
Inputs
- OidcConfig {issuer,clientId,redirectUri,postLogoutRedirectUri,scopes}
- Protected-route location and Keycloak authorization response {code,state}
Outputs
- Redirect URL containing response_type=code, code_challenge_method=S256, state, nonce, and allowed redirect_uri
- SessionState authenticated with access-token expiry and restored internal intended route
Failure boundaries
- Reject state/nonce mismatch, reused callback, missing code, discovery issuer mismatch, and callback error; clear the pending transaction.
- Reject intended routes with an origin, protocol-relative path, or control characters and restore / instead.
Excluded scope
- AeroSim account registration, password capture, social-provider brokering, Keycloak realm administration, and durable browser token storage are excluded.
Verification steps
- pnpm --filter @aerosim/web test -- auth/session-client.test.tsx
- Start at /foundation-status?tab=build, complete a valid callback, then test mismatched state, replay, external intended URL, and expired renewal token.
Traceability
Dependencies
- AEROSIM-TS-13Canonical ID: TASK-0013
- AEROSIM-TS-16Canonical ID: TASK-0016
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #22 reviewed head 2fb70c85a33341f8f9acd93f6681460f6d0cf960, exact-head validation task 1821 succeeded, merged as 39e9b71b6c00b5152fa02bc17a17a0ed1372b864; Wave 4 integrated application head e8bfe781d3295d445cbc46b297874f066cac8301 passed publish task 1832 and validate task 1833. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.