feat(coweft): central OIDC identity and delegated grants for the CoWeft subproject - #480
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
CoWeft UI source has been redesigned in the child, not replaced by concept images. This branch now pins Child verification: https://github.com/TokenNotIncluded/coweft/actions/runs/35734277580 — all Rust, web and Docker-build jobs succeeded. Browser report: 31 passed, 0 failed, with only the redundant mobile walkthrough skipped. Twelve real frontend screenshots and a real desktop browser recording are in the child run's See TokenNotIncluded/coweft#1 and its |
The repository contract test forbids a root deploy/ directory: deployment behavior lives in the Go and Rust backend CLIs, and the shell deploy/ tree was retired deliberately. Adding deploy/coweft/oidc.env.example recreated that directory, so TestRepositoryDeploymentBehaviorLivesInBackendCLIs failed on its first assertion in the Go default backend, Go full server qualification, and release artifact contract jobs. Move the example to packaging/common/lmm-api/lmm-oidc.env.example, matching the existing packaging convention, where component runtime examples ship next to their systemd units and packaging scripts. Update the single reference in docs/coweft-identity.md. No OIDC provider logic changes. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Paired delivery
CoWeft implementation: TokenNotIncluded/coweft#1. This change pins its tested revision
648c58ca2ec59113f54fd2f66fc9ea060585dc9aunderapps/coweft.LMM owns identity, authentication, consent and authorization. CoWeft consumes those grants as an OIDC relying party and MCP resource server; it does not create a separate account system.
Changes
https://api.lmm.best/oidc, with OIDC/RFC 8414 discovery, JWKS, authorization-code + S256 PKCE, RS256 ID tokens, userinfo, rotating opaque refresh/access grants, introspection and revocation.Compatibility / activation
Disabled by default. Existing native OAuth endpoints and clients remain unchanged. No production domain, key, client registration, secret, payment/model key or deployment was modified. Enable only after supplying the actual HTTPS origin, separate resource secret, RSA key and trusted proxy ranges. New disabled endpoints return 404, not the SPA.
Verification
The provider revision before this final docs/gitlink-only commit passed
go test -race ./oidcproviderandgo test ./service ./router -run 'OIDC|OAuth' -count=1(run 35722702802). Paired CoWeft revision passed Rust/PostgreSQL tests, real Go-to-Rust public-receipt verification, frontend compilation, six desktop/mobile browser tests and a locked-dependency Docker image build (run 35723110643). This PR also triggers checks for its exact head.Explicit boundaries
This is not OpenID certification or an independent security audit. Overlapping signing-key rotation is not implemented. Grant management is capped at 100 recent families; persistent expiry cleanup runs on startup and needs scheduled operational cleanup for long-running instances. OAuth identifies accounts, not unique natural people. CoWeft federation currently covers public-thread snapshots, not ActivityPub/global voting/migration/deletion guarantees. These limits and deployment verification requirements are documented rather than hidden behind a claim of complete decentralization.