AEROSIM-TS-56
Verify the SSO boundary and absence of local credentials
Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-30
- Component
- Web Application and API Service — authentication test suites
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Add unit, integration, browser, and adversarial tests for unauthenticated redirects, callback success and failure, token refresh and expiry, logout, forged or wrong-issuer tokens, HTTP and socket authorization, route restoration, and absence of password fields, password persistence, registration endpoints, and local sign-in paths. Concrete artifacts are tests/security/sso-boundary.test.ts and tests/browser/sso-boundary.spec.ts; ownership is limited to the listed artifacts and their focused verification.
Implementation contract
Implementation artifacts
- tests/security/sso-boundary.test.ts
- tests/browser/sso-boundary.spec.ts
Inputs
- Configured Keycloak test realm or deterministic OIDC fixture with approved issuer and audience
- Protected browser routes, HTTPS endpoints, and Socket.IO handshake fixtures
- Forged, expired, wrong-issuer, wrong-audience, callback-error, and logout test cases
Outputs
- Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.
Failure boundaries
- The suite fails if any invalid session reaches a protected HTTP or socket handler or if route restoration succeeds from an invalid callback
- The suite fails if a registration endpoint, password field, password column, local sign-in route, or credential persistence path is detected
Excluded scope
- Testing Keycloak account provisioning, password reset, or MFA policy
- Treating a mocked redirect alone as proof of the complete browser-to-API identity boundary
Verification steps
- Run tests/browser/sso-boundary.spec.ts against the exact implementation revision and retain the complete passing result.
- Exercise the positive contract with configured keycloak test realm or deterministic oidc fixture with approved issuer and audience, then assert: Reviewed automated and browser evidence demonstrates the approved Keycloak flow, stable subject propagation, denial of invalid or expired sessions, and absence of AeroSim registration or local-password fallback.
- Exercise every negative boundary: The suite fails if any invalid session reaches a protected HTTP or socket handler or if route restoration succeeds from an invalid callback; The suite fails if a registration endpoint, password field, password column, local sign-in route, or credential persistence path is detected
Traceability
Dependencies
- AEROSIM-TS-55Canonical ID: TASK-0055
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #57 merged the complete SSO boundary as b065bea3a34d9157d80e007f6f4bf9f8352b69e4; current integration retains Keycloak-only HTTP, Socket.IO, callback, refresh, expiry, logout, invalid-token, and no-local-credential coverage; focused security tests pass 15/15, browser-artifact tests pass 7/7, and browser boundary tests pass 12/12; exact-head integration validation and immutable image publication passed remotely at ade1706b80d1642a6763f2827cfb2e6b3fc8ddaf. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.