Commit Graph

17 Commits

Author SHA1 Message Date
Bastian Wagner
1d2467049d feat: fully backend-driven OIDC session flow (session cookie, not bearer token)
Replace the hybrid flow (frontend PKCE + POST /auth/session token
exchange, access token in sessionStorage) with a classic backend-driven
BFF: the browser only ever navigates to GET /api/v1/auth/login and is
redirected straight to the IdP; PKCE verifier/state live server-side in
Redis (SessionStoreService); GET /api/v1/auth/callback (now the
registered IdP redirect URI, replacing the frontend's /auth/callback
route, which is deleted) verifies the id_token, JIT-provisions the
user, creates a Redis-backed session, and sets one httpOnly SameSite=Lax
cookie before redirecting into the app. No token material of any kind
ever reaches the browser.

OidcAuthGuard (per-request bearer JWT verification) is replaced by
SessionAuthGuard (cookie -> Redis session lookup) across every
controller that used it. cookie-parser is now wired into main.ts.

Frontend AuthService shrinks to login()/logout()/ensureSessionChecked();
pkce.ts, auth.interceptor.ts, and the callback component/route are all
removed as dead code under this model.

New required env var: APP_BASE_URL (source of truth for the OIDC
redirect_uri and the post-login redirect target).

Verified end-to-end against the real API, Redis, and a mocked IdP:
login redirect shape, callback cookie + redirect, state-replay
rejection, /users/me 401<->200 around the cookie, and logout.
2026-08-17 17:33:55 +02:00
Bastian Wagner
4aca6b64a0 style: prettier formatting 2026-08-17 16:43:15 +02:00
Bastian Wagner
981cecbcbd feat: switch oidc client to confidential (backend token exchange)
The provisioned IdP client (https://auth.forgecore.work) is confidential
rather than public/PKCE-only, so a client secret must never reach the
browser. The frontend now only performs the Authorization Code + PKCE
redirect itself (hand-rolled PKCE, oidc-client-ts dependency removed)
and hands the resulting code + verifier to a new, intentionally
unauthenticated POST /api/v1/auth/session endpoint, which performs the
code-for-tokens exchange server-side using OIDC_CLIENT_SECRET and
returns only {accessToken, expiresIn} — refresh_token/id_token are
never forwarded to the client.

New required backend env vars: OIDC_CLIENT_ID, OIDC_CLIENT_SECRET.
Added frontend/proxy.conf.json so the Angular dev server forwards
/api and /health to the local API without needing CORS.
2026-08-17 16:36:49 +02:00
Bastian Wagner
dedb3fff40 feat: add trip preference overrides with precedence resolution 2026-08-17 15:38:03 +02:00
Bastian Wagner
ee7ec94ea0 feat: add traveler entity distinct from trip membership 2026-08-17 15:28:35 +02:00
Bastian Wagner
6954024622 feat: add trip invitation creation and acceptance flow 2026-08-17 15:21:08 +02:00
Bastian Wagner
baae15dcbc feat: enforce trip membership and role authorization 2026-08-17 15:13:23 +02:00
Bastian Wagner
ddf1d03447 feat: add trip and trip settings with optimistic locking 2026-08-17 15:06:00 +02:00
Bastian Wagner
2eb1692216 feat: expose current user and preference endpoints 2026-08-17 14:59:01 +02:00
Bastian Wagner
5abc7cbe29 feat: verify oidc bearer tokens and jit-provision users 2026-08-17 14:54:42 +02:00
Bastian Wagner
ec95a8e527 feat: add versioned migrations and kysely query layer 2026-08-17 14:33:28 +02:00
Bastian Wagner
a7ce7c3730 fix: wire version module into api module 2026-08-17 14:09:13 +02:00
Bastian Wagner
74ae283fea feat: expose safe build metadata and verify foundation 2026-08-17 14:08:56 +02:00
Bastian Wagner
2994e46274 ci: add teamcity build and deployment entry points 2026-08-17 13:53:01 +02:00
Bastian Wagner
0815f702d2 feat: add api liveness and readiness checks 2026-08-17 13:39:15 +02:00
Bastian Wagner
ceaef3028f feat: validate backend runtime configuration 2026-08-17 13:26:38 +02:00
Bastian Wagner
a08eecd4e3 feat: add nestjs api and worker skeletons 2026-08-17 13:18:24 +02:00