Skip to main content

AEROSIM-TS-57

Project task

Add the unique Keycloak-subject pilot linkage

The data model can store exactly one AeroSim pilot profile for each Keycloak subject without storing identity-provider credentials.

AEROSIM-TS-57Canonical ID TASK-0057
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Pilot Data Store — Pilot identity linkage and Prisma schema/migrations
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Define the Pilot profile and identity-linkage Prisma schema, require a unique non-null Keycloak subject identifier, add timestamps and safe profile defaults, create a reversible migration, and prohibit password or local-credential columns. Concrete artifacts are prisma/schema.prisma and tests/integration/add-the-unique-keycloak-subject-pilot-linkage.spec.ts; ownership is limited to the listed artifacts and their focused verification.

Implementation contract

Implementation artifacts

  • prisma/schema.prisma
  • prisma/migrations/add-the-unique-keycloak-subject-pilot-linkage/migration.sql
  • tests/integration/add-the-unique-keycloak-subject-pilot-linkage.spec.ts

Inputs

  • Authenticated Keycloak subject identifier used as the external identity key
  • Pilot profile defaults and timestamp policy
  • Current Prisma schema and migration baseline

Outputs

  • The data model can store exactly one AeroSim pilot profile for each Keycloak subject without storing identity-provider credentials.

Failure boundaries

  • Reject null, empty, or duplicate subject identifiers and roll back migrations that cannot preserve the one-subject-to-one-profile invariant
  • Prevent schema changes that add password hashes, local credentials, or identity-provider tokens to pilot records

Excluded scope

  • Copying Keycloak account credentials or complete identity-provider profiles into AeroSim
  • Supporting multiple pilot profiles for one Keycloak subject

Verification steps

  • Run tests/integration/add-the-unique-keycloak-subject-pilot-linkage.spec.ts against the exact implementation revision and retain the complete passing result.
  • Exercise the positive contract with authenticated keycloak subject identifier used as the external identity key, then assert: The data model can store exactly one AeroSim pilot profile for each Keycloak subject without storing identity-provider credentials.
  • Exercise every negative boundary: Reject null, empty, or duplicate subject identifiers and roll back migrations that cannot preserve the one-subject-to-one-profile invariant; Prevent schema changes that add password hashes, local credentials, or identity-provider tokens to pilot records

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #59 merged the unique Keycloak-subject pilot linkage as a46f0bb6f8214be18d6605706168f77f0be7ddab; current integration retains the non-null unique subject, safe defaults, reversible migration, and no-local-credential boundary; the focused PostgreSQL integration suite passes 11/11 against a disposable migrated database; exact-head integration validation and immutable image publication passed remotely at ade1706b80d1642a6763f2827cfb2e6b3fc8ddaf. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.