Skip to main content

AEROSIM-TS-56

Project task

Verify the SSO boundary and absence of local credentials

Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.

AEROSIM-TS-56Canonical ID TASK-0056
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application and API Service — authentication test suites
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Add unit, integration, browser, and adversarial tests for unauthenticated redirects, callback success and failure, token refresh and expiry, logout, forged or wrong-issuer tokens, HTTP and socket authorization, route restoration, and absence of password fields, password persistence, registration endpoints, and local sign-in paths. Concrete artifacts are tests/security/sso-boundary.test.ts and tests/browser/sso-boundary.spec.ts; ownership is limited to the listed artifacts and their focused verification.

Implementation contract

Implementation artifacts

  • tests/security/sso-boundary.test.ts
  • tests/browser/sso-boundary.spec.ts

Inputs

  • Configured Keycloak test realm or deterministic OIDC fixture with approved issuer and audience
  • Protected browser routes, HTTPS endpoints, and Socket.IO handshake fixtures
  • Forged, expired, wrong-issuer, wrong-audience, callback-error, and logout test cases

Outputs

  • Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.

Failure boundaries

  • The suite fails if any invalid session reaches a protected HTTP or socket handler or if route restoration succeeds from an invalid callback
  • The suite fails if a registration endpoint, password field, password column, local sign-in route, or credential persistence path is detected

Excluded scope

  • Testing Keycloak account provisioning, password reset, or MFA policy
  • Treating a mocked redirect alone as proof of the complete browser-to-API identity boundary

Verification steps

  • Run tests/browser/sso-boundary.spec.ts against the exact implementation revision and retain the complete passing result.
  • Exercise the positive contract with configured keycloak test realm or deterministic oidc fixture with approved issuer and audience, then assert: Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.
  • Exercise every negative boundary: The suite fails if any invalid session reaches a protected HTTP or socket handler or if route restoration succeeds from an invalid callback; The suite fails if a registration endpoint, password field, password column, local sign-in route, or credential persistence path is detected

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #57 merged the complete SSO boundary as b065bea3a34d9157d80e007f6f4bf9f8352b69e4; current integration retains Keycloak-only HTTP, Socket.IO, callback, refresh, expiry, logout, invalid-token, and no-local-credential coverage; focused security tests pass 15/15, browser-artifact tests pass 7/7, and browser boundary tests pass 12/12; exact-head integration validation and immutable image publication passed remotely at ade1706b80d1642a6763f2827cfb2e6b3fc8ddaf. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.