Skip to main content

Access AeroSim Through Keycloak SSO

Overview​

User capability

Authenticate through Keycloak without registration or local credentials

User

An AeroSim player

What the user can do

Authenticate through Keycloak without registration or local credentials

Why the user benefits

The player receives one coherent, observable capability.

User need

The player needs AeroSim to authenticate through Keycloak without registration or local credentials.

In scope

Authenticate through Keycloak without registration or local credentials

Tasks​

AEROSIM-TS-53Planning status: Done

Implement the browser Keycloak authorization-code session

Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.

  • ComponentWeb Application — Keycloak session client
  • Depends onAEROSIM-TS-42
  • RequirementsFR-0037, NFR-0008
AEROSIM-TS-54Planning status: Done

Enforce Keycloak JWT validation at the API boundary

The API accepts only valid Keycloak access tokens and derives one immutable authenticated-subject context for protected HTTP and Socket.IO operations.

  • ComponentAPI Service — Keycloak identity guard and Socket.IO gateway
  • Depends onAEROSIM-TS-42
  • RequirementsFR-0037, NFR-0008
AEROSIM-TS-55Planning status: Done

Connect the authenticated browser session to AeroSim APIs

A successful SSO session supplies the same Keycloak subject identity to protected AeroSim HTTP and Socket.IO requests without creating or using local credentials.

  • ComponentWeb Application — Profile and catalogue API client and Socket.IO client
  • Depends onAEROSIM-TS-53, AEROSIM-TS-54
  • RequirementsFR-0037, NFR-0008
AEROSIM-TS-56Planning status: Done

Verify the SSO boundary and absence of local credentials

Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.

  • ComponentWeb Application and API Service — authentication test suites
  • Depends onAEROSIM-TS-55
  • RequirementsFR-0037, NFR-0008
AEROSIM-TS-118Planning status: Done

Conform the Entry and SSO screen to the approved design

The implemented Entry experience matches the approved orientation, copy, imagery, action placement, and SSO transition.

  • ComponentWeb Application — Release 1.0.0 user journey
  • Depends onAEROSIM-TS-56
  • RequirementsFR-0037, NFR-0008

Acceptance outcomes​

  1. 01

    Unauthenticated access uses the approved Keycloak SSO flow.

  2. 02

    Successful SSO establishes one AeroSim pilot identity without registration or local credentials.

Functional requirements and measurable criteria​

FR-0037

Access AeroSim Through Keycloak SSO

The system shall authenticate through Keycloak without registration or local credentials.

Acceptance 01

GivenAEROSIM-FT-30 is exercised within its governed scope under supported conditions

Whenthe primary capability path is completed

ThenUnauthenticated access uses the approved Keycloak SSO flow

EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.

Acceptance 02

GivenAEROSIM-FT-30 is exercised within its governed scope under supported conditions

Whenthe continuation or repeat path is completed

ThenSuccessful SSO establishes one AeroSim pilot identity without registration or local credentials

EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.

Non-functional requirements

Risks​

  • Risk

    Representative browser or input configurations may expose an unmet outcome.

Original source and prototype evidence​

Prototype and discovery boundary

Existing implementation is discovery evidence only; it establishes no current approval, acceptance, or release state.