Access AeroSim Through Keycloak SSO
Overview
Authenticate through Keycloak without registration or local credentials
User
An AeroSim player
What the user can do
Authenticate through Keycloak without registration or local credentials
Why the user benefits
The player receives one coherent, observable capability.
User need
The player needs AeroSim to authenticate through Keycloak without registration or local credentials.
In scope
Authenticate through Keycloak without registration or local credentials
- StatusProposed
- OwnerAeroSim Scope (proposed; not accepted)
- Parent EpicAEROSIM-EP-2
- Depends onAEROSIM-FT-50
Tasks
AEROSIM-TS-53Planning status: DoneImplement the browser Keycloak authorization-code session
Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.
- ComponentWeb Application — Keycloak session client
- Depends onAEROSIM-TS-42
- RequirementsFR-0037, NFR-0008
AEROSIM-TS-54Planning status: DoneEnforce Keycloak JWT validation at the API boundary
The API accepts only valid Keycloak access tokens and derives one immutable authenticated-subject context for protected HTTP and Socket.IO operations.
- ComponentAPI Service — Keycloak identity guard and Socket.IO gateway
- Depends onAEROSIM-TS-42
- RequirementsFR-0037, NFR-0008
AEROSIM-TS-55Planning status: DoneConnect the authenticated browser session to AeroSim APIs
A successful SSO session supplies the same Keycloak subject identity to protected AeroSim HTTP and Socket.IO requests without creating or using local credentials.
- ComponentWeb Application — Profile and catalogue API client and Socket.IO client
- Depends onAEROSIM-TS-53, AEROSIM-TS-54
- RequirementsFR-0037, NFR-0008
AEROSIM-TS-56Planning status: DoneVerify the SSO boundary and absence of local credentials
Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.
- ComponentWeb Application and API Service — authentication test suites
- Depends onAEROSIM-TS-55
- RequirementsFR-0037, NFR-0008
AEROSIM-TS-118Planning status: DoneConform the Entry and SSO screen to the approved design
The implemented Entry experience matches the approved orientation, copy, imagery, action placement, and SSO transition.
- ComponentWeb Application — Release 1.0.0 user journey
- Depends onAEROSIM-TS-56
- RequirementsFR-0037, NFR-0008
Acceptance outcomes
- 01
Unauthenticated access uses the approved Keycloak SSO flow.
- 02
Successful SSO establishes one AeroSim pilot identity without registration or local credentials.
Functional requirements and measurable criteria
Access AeroSim Through Keycloak SSO
The system shall authenticate through Keycloak without registration or local credentials.
Acceptance 01
GivenAEROSIM-FT-30 is exercised within its governed scope under supported conditions
Whenthe primary capability path is completed
ThenUnauthenticated access uses the approved Keycloak SSO flow
EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.
Acceptance 02
GivenAEROSIM-FT-30 is exercised within its governed scope under supported conditions
Whenthe continuation or repeat path is completed
ThenSuccessful SSO establishes one AeroSim pilot identity without registration or local credentials
EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.
Non-functional requirements
- NFR-0008 — Pilot identity security and data isolation
Every authenticated operation resolves only the active Keycloak subject’s pilot data; AeroSim stores no local password; cross-pilot access attempts are denied and produce reviewable security evidence.
Risks
- Risk
Representative browser or input configurations may expose an unmet outcome.
Original source and prototype evidence
- discord: Agreed eight-Epic portfolio and Feature decomposition.
- discord: Agreed eight-Epic portfolio and Feature decomposition continuation.
- discord: Keycloak SSO direction without registration or local sign-in.
- discord: RootAtSkic directed publication of the agreed Scope update.
Prototype and discovery boundary
Existing implementation is discovery evidence only; it establishes no current approval, acceptance, or release state.