Built-in OAuth2 login-challenge handler (todo §6); /oauth2/login resolves a Hydra login challenge via the Kratos session — skip→accept(subject), live session→accept(identity id), no session→bounce to /login?return_to back here so Kratos lands on the challenge once signed in. New src/hydra-admin.ts (fetch client: get/accept/reject login request + HydraError, mirrors the kratos/keto clients) + src/oauth-login.ts (pure resolveLoginChallenge); wired in app.ts (the absolute return URL derives from the request Host + the SECURE_COOKIES scheme — a spoofed Host can't escape, Kratos validates return_to against its allow-list; /login now bakes return_to into the flow init), config.hydraAdminUrl (default http://hydra:4445), server builds the client, compose web now gates on hydra healthy (the app consumes it). A stale/invalid/consumed challenge (Hydra 4xx — back button, slow login) degrades to a recoverable 400, not a 500; a genuine Hydra 5xx outage still surfaces as 500. Tests-first: hydra-admin/oauth-login units + app/config/compose HTTP integration + full-stack e2e/oauth-login.spec.ts (compose.e2e-oauth.yml — registers an OAuth2 client, starts an auth flow, asserts the unauthenticated bounce and the authenticated accept; boot-verified then torn down). Stability-reviewer run as a local PR: APPROVE, no Critical/High; addressed its one warning (4xx→400 degrade). Deferred §9: document that prod allowed_return_urls entries must be exact origins with a trailing /. typecheck + 253 units + 8 visual + oauth-login E2E green. Consent handler + client registration are the next §6 items.
This commit is contained in:
+4
-3
@@ -1,7 +1,7 @@
|
||||
// Guards the dev/prod compose split + stack ordering (§3): every image is pinned to an
|
||||
// exact version (AGENTS.md), long-running Ory services carry readiness healthchecks so
|
||||
// `depends_on: service_healthy` works, the web app waits for the services it talks to
|
||||
// (kratos + keto, per config.ts), prod publishes no internal Ory ports while dev exposes
|
||||
// (kratos + keto + hydra), prod publishes no internal Ory ports while dev exposes
|
||||
// the ones a browser must reach, and the visual E2E stays Ory-free. Real boot is verified
|
||||
// by running the stack; this catches edits.
|
||||
import { test } from "node:test";
|
||||
@@ -40,9 +40,10 @@ test("long-running Ory services declare readiness healthchecks", () => {
|
||||
`${svc} probes :${port}/health/ready`);
|
||||
});
|
||||
|
||||
test("web waits for kratos and keto to be healthy before starting", () => {
|
||||
test("web waits for kratos, keto and hydra to be healthy before starting", () => {
|
||||
assert.match(webBlock, /depends_on:/, "web declares dependencies");
|
||||
for (const svc of ["kratos", "keto"])
|
||||
// hydra: the §6 OAuth2 login/consent handler talks to its admin API.
|
||||
for (const svc of ["kratos", "keto", "hydra"])
|
||||
assert.match(webBlock, new RegExp(`${svc}:\\s*\\n\\s*condition:\\s*service_healthy`),
|
||||
`web waits for ${svc} healthy`);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user