Skip to content

feat(verify): cover the OAuth migration cutover path - #217

Merged
Bccorb merged 1 commit into
mainfrom
feat/verify-oauth-cutover
Oct 6, 2026
Merged

Bccorb merged 1 commit into
mainfrom
feat/verify-oauth-cutover

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Part of fells-code/seamless-auth-api#337 (its last checklist item: conformance coverage for the link-then-enroll path).

What the new spec covers

verify/harness/api/oauthCutover.spec.ts, API layer, runs end to end against a real stack:

  1. As the owner admin, add an OIDC provider with issuer/jwksUri, externalIdSource + externalIdJsonPath: 'oid' and promptPasskeyEnrollment: true. Create an organization and import a user into it with a directory id.
  2. Sign in through the provider. The directory reports a different email than the imported one, so the link can only have come from oid. Assert sub is the imported user and nextStep is enroll_passkey.
  3. Enroll a passkey with that session, using a software authenticator (fmt: 'none') and the API's register start/finish.
  4. Sign in again and assert there is no nextStep.
  5. Retire the provider for the organization. Assert the user's access token and refresh token both answer 401, and the next sign-in answers 403 oauth_provider_retired.
  6. Restore the provider and assert the user signs in again.

Harness changes

  • mock-oidc.ts:
    • The token response now includes a signed ID token. The key is ES256 and derived from a fixed seed, with a stable kid, so a quick local re-run doesn't hit the API's JWKS refetch cooldown.
    • It serves /jwks.
    • It echoes the nonce and uses the client_id as aud.
    • /authorize takes mock_sub / mock_email / mock_oid to sign in as a named user.
    • The existing mock provider has no issuer, so it ignores the ID token and is unchanged.
  • lib/softwareAuthenticator.ts: a minimal ES256 authenticator with a small CBOR encoder, so the harness gains no dependency.
  • lib/cutoverFlows.ts: owner admin sign-in, provider creation, sign-in as a named directory user, passkey enrollment.

Merge order

Merge after fells-code/seamless-auth-api#348. Step 5's session revocation assertions need it.

Checks

  • Ran on a local verify stack (API from the #348 branch, its port remapped to sit beside another local stack):
    • The full api project passed (22 specs).
    • The two OAuth specs passed twice back to back.
  • npm test passes (1054). tsc --noEmit passes for the CLI and the new harness files.
  • While writing this, the first run surfaced something worth knowing. POST /admin/organizations makes the creating admin a member, so retiring a provider for that organization also signs the admin out. The spec asserts this and signs in again before restoring.

Import a directory user, link them through an OIDC provider on the ID
token's oid, enroll a passkey from nextStep, then retire the provider
for their organization and roll it back. The mock OIDC provider now
issues signed ID tokens from a fixed key and can sign in as a named user.

Part of fells-code/seamless-auth-api#337.
@Bccorb
Bccorb merged commit adf6ffd into main Oct 6, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant