Skip to main content

AEROSIM-TS-53

Project task

Implement the browser Keycloak authorization-code session

Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.

AEROSIM-TS-53Canonical ID TASK-0053
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application — Keycloak session client
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Implement route protection, PKCE authorization initiation and callback handling, token lifecycle, intended-route restoration, logout, and explicit authentication failures in the Web Application. Do not add registration, password collection, or local sign-in. Concrete artifacts are applications/web/src/auth/keycloak-session.ts and applications/web/src/auth/keycloak-session.test.ts; the module boundary owns browser OIDC session establishment and restoration.

Implementation contract

Implementation artifacts

  • applications/web/src/auth/keycloak-session.ts
  • applications/web/src/auth/keycloak-session.test.ts

Inputs

  • Keycloak authorization endpoint, client identifier, redirect URI, requested scopes, and PKCE S256 challenge
  • Protected browser route and intended return location
  • Authorization callback carrying either an authorization code and matching state or an OIDC error

Outputs

  • Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.

Failure boundaries

  • Reject callbacks with missing or mismatched state, absent code, invalid nonce, or failed token exchange without creating an AeroSim session
  • When refresh fails or the token expires, clear the browser session and require a new Keycloak authorization flow rather than continuing with stale credentials

Excluded scope

  • AeroSim registration, password collection, local sign-in, and storage of Keycloak credentials
  • Identity-provider administration, account recovery, and MFA enrollment

Verification steps

  • Run applications/web/src/auth/keycloak-session.test.ts against the exact implementation revision and retain the complete passing result.
  • Exercise the positive contract with keycloak authorization endpoint, client identifier, redirect uri, requested scopes, and pkce s256 challenge, then assert: Unauthenticated browser access redirects through the approved Keycloak OIDC Authorization Code with PKCE flow and returns with a usable AeroSim session.
  • Exercise every negative boundary: Reject callbacks with missing or mismatched state, absent code, invalid nonce, or failed token exchange without creating an AeroSim session; When refresh fails or the token expires, clear the browser session and require a new Keycloak authorization flow rather than continuing with stale credentials

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #46 reviewed head 98f240453d08fa48d828a113e9ff1db4c708624f, exact-head validation task 1911 succeeded, merged as e57de97282209c5e7dce5f4784fc108e4f44696b; Wave 8 integrated application head a3e4429a9970241b278a4f64aa7c6541c74e63a8 passed publish task 1916 and validate task 1917. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.