AEROSIM-TS-53
Implement the browser Keycloak authorization-code session
Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-30
- Component
- Web Application — Keycloak session client
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Implement route protection, PKCE authorization initiation and callback handling, token lifecycle, intended-route restoration, logout, and explicit authentication failures in the Web Application. Do not add registration, password collection, or local sign-in. Concrete artifacts are applications/web/src/auth/keycloak-session.ts and applications/web/src/auth/keycloak-session.test.ts; the module boundary owns browser OIDC session establishment and restoration.
Implementation contract
Implementation artifacts
- applications/web/src/auth/keycloak-session.ts
- applications/web/src/auth/keycloak-session.test.ts
Inputs
- Keycloak authorization endpoint, client identifier, redirect URI, requested scopes, and PKCE S256 challenge
- Protected browser route and intended return location
- Authorization callback carrying either an authorization code and matching state or an OIDC error
Outputs
- Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.
Failure boundaries
- Reject callbacks with missing or mismatched state, absent code, invalid nonce, or failed token exchange without creating an AeroSim session
- When refresh fails or the token expires, clear the browser session and require a new Keycloak authorization flow rather than continuing with stale credentials
Excluded scope
- AeroSim registration, password collection, local sign-in, and storage of Keycloak credentials
- Identity-provider administration, account recovery, and MFA enrollment
Verification steps
- Run applications/web/src/auth/keycloak-session.test.ts against the exact implementation revision and retain the complete passing result.
- Exercise the positive contract with keycloak authorization endpoint, client identifier, redirect uri, requested scopes, and pkce s256 challenge, then assert: Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.
- Exercise every negative boundary: Reject callbacks with missing or mismatched state, absent code, invalid nonce, or failed token exchange without creating an AeroSim session; When refresh fails or the token expires, clear the browser session and require a new Keycloak authorization flow rather than continuing with stale credentials
Traceability
Dependencies
- AEROSIM-TS-42Canonical ID: TASK-0042
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #46 reviewed head 98f240453d08fa48d828a113e9ff1db4c708624f, exact-head validation task 1911 succeeded, merged as e57de97282209c5e7dce5f4784fc108e4f44696b; Wave 8 integrated application head a3e4429a9970241b278a4f64aa7c6541c74e63a8 passed publish task 1916 and validate task 1917. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.