AEROSIM-TS-55
Connect the authenticated browser session to AeroSim APIs
A successful SSO session supplies the same Keycloak subject identity to protected AeroSim HTTP and Socket.IO requests without creating or using local credentials.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-30
- Component
- Web Application — Profile and catalogue API client and Socket.IO client
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Attach bearer tokens to HTTPS/JSON requests and authenticated Socket.IO connections, handle refresh and expiry consistently, reject subject-free application state, and clear authenticated clients on logout. Concrete artifacts are applications/web/src/auth/aerosim-api-client.ts and applications/web/src/auth/aerosim-api-client.test.ts; ownership is limited to the listed artifacts and their focused verification.
Implementation contract
Implementation artifacts
- applications/web/src/auth/aerosim-api-client.ts
- applications/web/src/auth/aerosim-api-client.test.ts
Inputs
- Usable Keycloak access token and immutable subject from the established browser session
- Protected AeroSim HTTPS request or Socket.IO connection request
- Token refresh, expiry, and logout events from the session client
Outputs
- A successful SSO session supplies the same Keycloak subject identity to protected AeroSim HTTP and Socket.IO requests without creating or using local credentials.
Failure boundaries
- Do not issue a protected request or open a socket when no usable token or subject is present
- On refresh failure, expiry, subject change, or logout, disconnect sockets, clear protected clients, and discard pilot-bound browser state
Excluded scope
- Sending a subject identifier supplied by page state as proof of identity
- Persisting bearer or refresh tokens as local pilot credentials
Verification steps
- Run applications/web/src/auth/aerosim-api-client.test.ts against the exact implementation revision and retain the complete passing result.
- Exercise the positive contract with usable keycloak access token and immutable subject from the established browser session, then assert: A successful SSO session supplies the same Keycloak subject identity to protected AeroSim HTTP and Socket.IO requests without creating or using local credentials.
- Exercise every negative boundary: Do not issue a protected request or open a socket when no usable token or subject is present; On refresh failure, expiry, subject change, or logout, disconnect sockets, clear protected clients, and discard pilot-bound browser state
Traceability
Dependencies
- AEROSIM-TS-53Canonical ID: TASK-0053
- AEROSIM-TS-54Canonical ID: TASK-0054
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: original application PR #50 merged reviewed head e0251eb3a6095bd2e2236254f361411e0841fab7 as 3dc5356fad43721ffc2d108cb6622263341e786e; 72 authenticated-client tests and current lint/typecheck passed on current integration; duplicate verification PR #127 was closed unmerged after exact-head CI run 4226 passed; current integrated publication and validation runs 4230 and 4231 passed. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.