Skip to main content

AEROSIM-TS-60

Project task

Verify profile idempotency and cross-pilot isolation

Reviewed evidence demonstrates first-session creation, repeated-session reuse, concurrency-safe non-duplication, and denial of access to another subject's pilot profile.

AEROSIM-TS-60Canonical ID TASK-0060
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Pilot Data Store, API Service, and Web Application — pilot-profile test suites
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Add migration, service, API, concurrency, and browser tests using at least two Keycloak subjects; prove one profile per subject, stable profile identity across sessions, no duplicate creation under simultaneous requests, rejection of caller-supplied subject substitution, and no stored local credentials. Concrete artifacts are prisma/schema.prisma and tests/integration/verify-profile-idempotency-and-cross-pilot-isolation.spec.ts; ownership is limited to the listed artifacts and their focused verification.

Implementation contract

Implementation artifacts

  • prisma/schema.prisma
  • prisma/migrations/verify-profile-idempotency-and-cross-pilot-isolation/migration.sql
  • tests/integration/verify-profile-idempotency-and-cross-pilot-isolation.spec.ts

Inputs

  • Two distinct Keycloak-subject fixtures plus repeated and concurrent current-profile requests
  • Fresh and migrated Pilot schema instances
  • Browser login, logout, and later-login scenarios

Outputs

  • Reviewed evidence demonstrates first-session creation, repeated-session reuse, concurrency-safe non-duplication, and denial of access to another subject's pilot profile.

Failure boundaries

  • Fail if concurrent requests create duplicate profiles or later sessions resolve a different profile identifier for the same subject
  • Fail on any cross-subject profile disclosure, caller-supplied subject substitution, or stored local credential field

Excluded scope

  • Load testing unrelated profile endpoints
  • Validating identity-provider account management outside AeroSim

Verification steps

  • Run tests/integration/verify-profile-idempotency-and-cross-pilot-isolation.spec.ts against the exact implementation revision and retain the complete passing result.
  • Exercise the positive contract with two distinct keycloak-subject fixtures plus repeated and concurrent current-profile requests, then assert: Reviewed evidence demonstrates first-session creation, repeated-session reuse, concurrency-safe non-duplication, and denial of access to another subject's pilot profile.
  • Exercise every negative boundary: Fail if concurrent requests create duplicate profiles or later sessions resolve a different profile identifier for the same subject; Fail on any cross-subject profile disclosure, caller-supplied subject substitution, or stored local credential field

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #83 reviewed head 731c5a8a29b1552da5d6527c110b2047ce811ee5, merged as 2dcc2edb615fb952bbc57dc4313f26f603407267; final whole-wave application head 7f26eca79eadef3171564fc60035e9866c2c848e: publication run 3914 succeeded and integration run 3915 succeeded. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.