AEROSIM-TS-42
Verify Keycloak redirect, return, and rejection flows
Automated integration tests prove intended-route restoration, authenticated API access, and rejection of missing, invalid, expired, or incorrectly scoped tokens.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-50
- Component
- Web Application and API Service — Keycloak integration tests
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Exercise Nebula and Singularity against a controlled OIDC fixture: redirect from a protected deep link, valid callback and route restoration, authorized API request, logout, and rejection of missing, malformed, bad-signature, expired, wrong-issuer, and wrong-audience tokens. Primary files: tests/integration/auth/keycloak-flow.spec.ts, tests/integration/auth/keycloak-fixture.ts, tests/integration/auth/jwt-fixtures.ts.
Implementation contract
Implementation artifacts
- tests/integration/auth/keycloak-flow.spec.ts
- tests/integration/auth/keycloak-fixture.ts
- tests/integration/auth/jwt-fixtures.ts
Inputs
- Controlled Keycloak discovery/JWKS endpoints and authorization-code fixture
- Deep link /foundation-status?tab=build and JWT matrix for subject pilot-alpha
Outputs
- Browser trace from protected route through Keycloak callback back to the exact internal deep link
- API status matrix proving valid=200 and every invalid token=401 while health=200
Failure boundaries
- No invalid callback may establish SessionState or send a bearer token to Singularity.
- No rejected API token may invoke the protected handler or disclose claim, signature, or key material.
Excluded scope
- Production realm provisioning, federation, MFA policy, and identity-provider uptime testing are excluded.
Verification steps
- pnpm test:integration -- keycloak-flow.spec.ts
- After the valid flow, replay callback state and run the seven token cases; assert session/handler counters remain unchanged on rejection.
Traceability
Dependencies
- AEROSIM-TS-41Canonical ID: TASK-0041
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #42 reviewed head e9ecbe42d6c46c5f48ad0f2d9b02db89d26a4ae7, exact-head validation task 1896 succeeded, merged as b75d00b8c3864752bf5b1ea0298097add346f0aa; Wave 7 integrated application head b75d00b8c3864752bf5b1ea0298097add346f0aa passed publish task 1899 and validate task 1900. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.