Commit graph

1504 commits

Author SHA1 Message Date
XiaoSeS
b7cfbe193b fix(auth): serialize account merges and revoke secondary tokens
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-10-08 13:56:23 +08:00
XiaoSeS
7a53782985 test(auth): bound row lock fixture wait
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-10-08 12:20:51 +08:00
XiaoSeS
15abf9ce76 test(auth): verify merge row lock contention
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-10-08 12:18:19 +08:00
XiaoSeS
291f5fc24f test(auth): cover merge cancellation races
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-10-08 12:15:13 +08:00
XiaoSeS
dc635a24d6 fix(auth): require secondary approval before account merge
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-10-08 12:03:55 +08:00
XiaoSeS
735259728f
Merge pull request #904 from iflytek/docs/weekly-w39-official-signed
Some checks failed
Deploy Docs / build (push) Has been cancelled
Security / Dependency Review (push) Has been cancelled
Security / CodeQL (java-kotlin) (push) Has been cancelled
Security / CodeQL (javascript-typescript) (push) Has been cancelled
Security / CodeQL (python) (push) Has been cancelled
Deploy Docs / Deploy (push) Has been cancelled
docs(weekly): publish 2026-W39 report
2026-09-24 18:29:41 +08:00
XiaoSeS
903228b350 docs(weekly): publish 2026-W39 report
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 18:24:38 +08:00
XiaoSeS
455cbb5ba5
Merge pull request #902 from iflytek/feature/enterprise-login-r1b2-org-admin
feat(auth): add organization creation control plane slice
2026-09-24 15:58:57 +08:00
dongmucat
0fd222d1e7
Merge pull request #879 from iflytek/feature/scanner-2-1-upgrade
fix(scanner): harden Scanner 2.1 integration
2026-09-24 15:47:20 +08:00
XiaoSeS
17273bb6ca docs(auth): decouple organization APIs from OIDC controls
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 15:44:56 +08:00
XiaoSeS
1e2de2798b test(auth): verify organization creation rollback
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 15:14:16 +08:00
dongmucat
9f92debf00 fix(scanner): redact mounted route findings
Signed-off-by: dongmucat <1127093059@qq.com>
2026-09-24 15:01:28 +08:00
XiaoSeS
52e4e052a1 feat(auth): add organization creation control plane slice
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 14:43:17 +08:00
XiaoSeS
39a7081ff4
Merge pull request #901 from iflytek/feature/login-page-refresh-pr
feat(auth): refresh login and registration entry
2026-09-24 14:08:33 +08:00
XiaoSeS
e0c5f7597d test(auth): expect home after registration
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:53:00 +08:00
XiaoSeS
69192fcf9b test(auth): match theme toggle accessible name
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:35:31 +08:00
XiaoSeS
f9e9496053 test(auth): stabilize registration layout screenshot
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:35:31 +08:00
XiaoSeS
3000375515 test(auth): cover registration viewport and artwork loading
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:35:31 +08:00
XiaoSeS
f8148f28f6 test(auth): cover direct routing and login layout boundaries
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:35:30 +08:00
XiaoSeS
e4ee6b6d9a fix(auth): keep login available during session check failures
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 13:35:30 +08:00
XiaoSeS
8249e84454 fix(auth): hide password routing implementation details
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 11:22:43 +08:00
XiaoSeS
0e9d2e2d3e fix(auth): redirect signed-in visitors away from login
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 11:22:43 +08:00
XiaoSeS
5be60043d5 test(auth): select password field precisely
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 10:32:21 +08:00
XiaoSeS
5aea7345b8 test(auth): cover registration and runtime return navigation
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 10:21:38 +08:00
XiaoSeS
1aa8d7bc85 fix(auth): guard registration OAuth hint and return paths
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 10:09:55 +08:00
XiaoSeS
5a8b796d03 fix(auth): defer organization discovery until backend contract
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 09:48:56 +08:00
XiaoSeS
5d4b40a5e5 fix(auth): return to origin or home after login
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-24 09:37:15 +08:00
XiaoSeS
ff077bfbe7 fix(auth): hide unavailable method catalog warning
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-23 17:12:34 +08:00
XiaoSeS
c8e6988485 feat(auth): refresh login and registration entry
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-23 17:02:50 +08:00
XiaoSeS
e8fad5962e
fix(web): refresh API proxy DNS after backend redeploy (#900)
Some checks are pending
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
* fix(web): refresh API proxy DNS after backend redeploy

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>

* test(web): stabilize DNS replacement coverage

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>

* test(web): allow early resolver refresh after DNS change

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>

* test(web): use dynamic ports for nginx smoke

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>

---------

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-23 15:51:08 +08:00
XiaoSeS
ed2ff97d00
Merge pull request #897 from iflytek/feature/enterprise-login-r1b1
Some checks failed
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
Deploy Docs / build (push) Has been cancelled
Deploy Docs / Deploy (push) Has been cancelled
feat(auth): add organization control-plane read APIs
2026-09-22 17:52:22 +08:00
XiaoSeS
da317d94e9 feat(auth): add organization control-plane read APIs
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 16:38:10 +08:00
XiaoSeS
5f91069cc2
Merge pull request #876 from strawberryOJam/main
docs(readme): fix backend development command
2026-09-22 16:13:27 +08:00
XiaoSeS
cc6e998ea1
Merge pull request #896 from iflytek/feat/identity-provider-adapter-contracts
feat(auth): add identity provider adapter contracts
2026-09-22 16:13:20 +08:00
XiaoSeS
5c629f7cfa
Merge pull request #878 from iflytek/codex/handle/issues-861-853-20260918
feat(builtin-skills): add orca replay and yylo ledger tasks
2026-09-22 16:02:38 +08:00
XiaoSeS
17da5d1e3f feat(auth): validate built-in adapter contracts
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 15:55:56 +08:00
XiaoSeS
4f06e69224 feat(auth): define enterprise identity contracts
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 15:36:55 +08:00
XiaoSeS
5aa038d188 fix(builtin-skills): accept immutable CDN UUID filenames
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 15:27:13 +08:00
XiaoSeS
3de0b94a9a
fix(auth): harden oauth token and claim logging (#895)
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 15:24:31 +08:00
strawberryOJam
9991938983
Merge branch 'iflytek:main' into main 2026-09-22 13:02:30 +08:00
XiaoSeS
8498fd047f
Merge pull request #880 from iflytek/feature/dingtalk-public-provider
feat(auth): add DingTalk as a public login provider (R1-A2)
2026-09-22 11:02:22 +08:00
XiaoSeS
50e7427596 docs(deploy): complete DingTalk private deployment guide
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 10:47:28 +08:00
XiaoSeS
00033b1b92 docs(deploy): document DingTalk egress requirements
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 10:47:28 +08:00
XiaoSeS
36f5f06d9c fix(auth): diagnose DingTalk userinfo failures
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-22 10:47:28 +08:00
XiaoSeS
ca4de37d08 docs(deploy): add DingTalk provider acceptance steps
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 16:08:32 +08:00
XiaoSeS
1297e87c5a fix(deploy): complete DingTalk runtime configuration
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00
XiaoSeS
d92e1f8216 fix(auth): preserve provider token routing and error bounds
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00
XiaoSeS
b1f1b18737 fix(auth): stop the DingTalk callback being routed to the OIDC provider
The DingTalk login could not complete. Adding openid to the authorization
request's scope set avoided the nonce at the authorize step but broke the
callback: OAuth2LoginAuthenticationProvider.authenticate returns null when
getScopes() contains "openid", handing the exchange to
OidcAuthorizationCodeAuthenticationProvider, which fails with
invalid_id_token because DingTalk returns no id_token. Neither the token
client nor the user service was ever reached. spring-security-oauth2-jose is
on the runtime classpath, so that provider is registered.

The scope now goes onto the outgoing authorization URI directly, leaving
getScopes() empty. Both openid-keyed mechanisms are then avoided: no nonce,
because the registration still declares no scope in configuration, and no
OIDC routing, because the request carries no openid scope.

The previous test asserted getScopes() contains "openid" -- the exact state
that breaks the callback -- so it locked the bug in. It now asserts the
inverse, and restoring the old implementation makes it fail.

Also switches the registration from client-authentication-method: none to
client-secret-post. "none" made Spring apply PKCE and emit a code_challenge
that DingTalkTokenResponseClient cannot answer, since its JSON token request
sends no code_verifier. It was also semantically wrong: DingTalk is a
confidential client that carries its secret in the request body.

Verified against a local staging instance: the authorization URI now carries
scope=openid with no nonce and no code_challenge, and a callback with a fake
code fails in the token exchange with no OIDC provider involvement in the
logs.

Drops SUBJECT_ATTRIBUTE, which lost its last reference when the user service
stopped pre-resolving the subject.

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00
XiaoSeS
629c1ced55 fix(auth): bound the DingTalk token response and log a rejected login
Two gaps from reviewing this batch against the Feishu adapter it mirrors.

The token exchange had no response size limit while the userinfo call did,
so the same hostile or misconfigured endpoint was bounded on one call and
unbounded on the other. Adds the same 64 KB cap through a RestTemplate
interceptor, which keeps the existing tests working against an injected
template. buildRestTemplate becomes package-visible so one test can exercise
the production template, cap included; removing the interceptor makes that
test fail.

A missing unionId threw without logging, unlike the equivalent Feishu
branch. This is a reachable failure -- DingTalk omits unionId for some app
configurations -- and an operator seeing every login rejected needs to know
why. Logs the claim name only, which says nothing about the user.

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00
XiaoSeS
75c7f9a880 feat(deploy): wire DingTalk credentials into the release surfaces
Adds the DingTalk credentials to every path that actually delivers
configuration: compose.release.yml (which has no env_file, so variables must
be listed explicitly), the Helm secret template and values, the k8s
deployment and its secret example. validate-release-config.sh gains DingTalk
in its provider loop, so a half-configured pair is rejected the same way.

Documents the three-stage strategy contract in the authentication design: a
table mapping each deviation -- authorize parameters, token exchange,
userinfo loading -- to its interface and current implementations, plus the
rule that a provider must never make account decisions itself.

Deployment notes and both FAQs now cover DingTalk, including the shared trap
with Feishu: their emails are admin-recorded and never confirmed, so
emailVerified is always false and an EMAIL_DOMAIN access policy would reject
every login through either provider.

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 15:15:41 +08:00