Skip to content

feat(coweft): central OIDC identity and delegated grants for the CoWeft subproject - #480

Merged
LIghtJUNction merged 10 commits into
mainfrom
feat/coweft-oidc
Sep 22, 2026
Merged

LIghtJUNction merged 10 commits into
mainfrom
feat/coweft-oidc

Conversation

@LIghtJUNction

Copy link
Copy Markdown
Collaborator

Paired delivery

CoWeft implementation: TokenNotIncluded/coweft#1. This change pins its tested revision 648c58ca2ec59113f54fd2f66fc9ea060585dc9a under apps/coweft.

LMM owns identity, authentication, consent and authorization. CoWeft consumes those grants as an OIDC relying party and MCP resource server; it does not create a separate account system.

Changes

  • Separate first-party subproject issuer https://api.lmm.best/oidc, with OIDC/RFC 8414 discovery, JWKS, authorization-code + S256 PKCE, RS256 ID tokens, userinfo, rotating opaque refresh/access grants, introspection and revocation.
  • Reuses existing LMM user/session validation, including session and user-auth versions. No group, rank, paid tier or spending is imported into forum privileges.
  • Explicit registered web/agent clients and resource audiences. Human/agent controller provenance comes from client registration while both map to the same immutable subject.
  • Consent and grant management under the existing refresh-cookie path. A same-site login bridge preserves the request without widening cookies or assuming frontend redirect support.
  • Persistent GORM records and atomic refresh-token consumption/replay tombstones; current-session and grant checks on resource use.
  • Public federation receipts require BOTH the origin resource credential and an active author grant. Dedicated JWT type/audience prevents confusing receipts with credentials; no secrets go to peers.
  • Configuration examples, deployment boundaries, CI, and the CoWeft git submodule.

Compatibility / activation

Disabled by default. Existing native OAuth endpoints and clients remain unchanged. No production domain, key, client registration, secret, payment/model key or deployment was modified. Enable only after supplying the actual HTTPS origin, separate resource secret, RSA key and trusted proxy ranges. New disabled endpoints return 404, not the SPA.

Verification

The provider revision before this final docs/gitlink-only commit passed go test -race ./oidcprovider and go test ./service ./router -run 'OIDC|OAuth' -count=1 (run 35722702802). Paired CoWeft revision passed Rust/PostgreSQL tests, real Go-to-Rust public-receipt verification, frontend compilation, six desktop/mobile browser tests and a locked-dependency Docker image build (run 35723110643). This PR also triggers checks for its exact head.

Explicit boundaries

This is not OpenID certification or an independent security audit. Overlapping signing-key rotation is not implemented. Grant management is capped at 100 recent families; persistent expiry cleanup runs on startup and needs scheduled operational cleanup for long-running instances. OAuth identifies accounts, not unique natural people. CoWeft federation currently covers public-thread snapshots, not ActivityPub/global voting/migration/deletion guarantees. These limits and deployment verification requirements are documented rather than hidden behind a claim of complete decentralization.

Copilot AI lite review requested due to automatic review settings September 22, 2026 11:51
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-22T12:02:07.239185Z 0632059 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Collaborator Author

CoWeft UI source has been redesigned in the child, not replaced by concept images. This branch now pins apps/coweft to 18c48476cef1eed869e1b32363576b2eed89514e (parent sync commit a372940b98ce51d2f4c62a4e6fffc8f314316281). These latest parent commits change only the child gitlink; they do not modify OIDC logic, secrets or production configuration.

Child verification: https://github.com/TokenNotIncluded/coweft/actions/runs/35734277580 — all Rust, web and Docker-build jobs succeeded. Browser report: 31 passed, 0 failed, with only the redundant mobile walkthrough skipped. Twelve real frontend screenshots and a real desktop browser recording are in the child run's web-verification artifact; discussion/AI data are explicitly mocked test fixtures.

See TokenNotIncluded/coweft#1 and its docs/frontend.md for the redesigned pages, functioning interactions and scope. The earlier PR description's child SHA and six-test count describe the previous version and are superseded by this update. Neither PR has been merged or deployed by this UI change.

The repository contract test forbids a root deploy/ directory: deployment
behavior lives in the Go and Rust backend CLIs, and the shell deploy/ tree was
retired deliberately. Adding deploy/coweft/oidc.env.example recreated that
directory, so TestRepositoryDeploymentBehaviorLivesInBackendCLIs failed on its
first assertion in the Go default backend, Go full server qualification, and
release artifact contract jobs.

Move the example to packaging/common/lmm-api/lmm-oidc.env.example, matching the
existing packaging convention, where component runtime examples ship next to
their systemd units and packaging scripts. Update the single reference in
docs/coweft-identity.md. No OIDC provider logic changes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@LIghtJUNction
LIghtJUNction merged commit f64e32d into main Sep 22, 2026
35 of 36 checks passed
@LIghtJUNction
LIghtJUNction deleted the feat/coweft-oidc branch September 22, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants