feat(auth): native SSO authorization bridge for the Android app
Add a Mobile SSO Authorization Bridge so the native app can "Sign in with Google/Discord" without shipping any OAuth secret. It EXTENDS the existing /auth/sso/* redirect flow (same PKCE-vs-IdP, link-only + opt-in provisioning, TOTP gate) and terminates in the existing mobile bearer tokens — not a parallel auth path. - Schema: mobile_auth_sessions + mobile_auth_codes (short-lived, self-pruning; authorization code stored hash-only, PKCE challenge is a hash by construction). - GET /auth/mobile/sso/start: validate provider enabled + redirect_uri by EXACT allowlist match (never prefix), seed a bridge session, reuse the SSO redirect tagged mode:'mobile' (new redirectToIdp helper extracted from beginFlow). - SSO callback + finishSsoTotp gain a mode:'mobile' branch: mint a single-use, hashed, PKCE-bound code and redirect to the fixed app callback (code + echoed state, never a token) instead of setting a cookie. 2FA keeps full parity via the existing web TOTP form (now carrying the bridge session). - POST /auth/mobile/sso/exchange: verify Layer-B PKCE (before burning the code), single-use consume, then issue the SAME pair as /auth/mobile/login. - Discovery reuses GET /auth/providers; refresh/logout reuse /auth/mobile/*. - Rate limits: /start per-IP+provider, /exchange per-IP. Boot-time + opportunistic prune of both tables (no cron, mirrors revoked_sessions). - Redirect allowlist is MOBILE_AUTH_REDIRECT_URIS (default the one fixed runicgateway://auth/callback); App Link URIs can be appended per shard later. - Swagger regenerated; 39 tests (model single-use/gating + full controller matrix: bad/expired/reused code, PKCE mismatch, disabled provider, redirect allowlist, TOTP-through-bridge). Full suite green (271). Refs docs/website/BACKEND_DESIGN.md, docs/android/PLAN.md §9 (M9). Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -185,6 +185,20 @@ const doc = {
|
||||
all: { type: 'boolean', description: 'Revoke every session for the user.', example: false },
|
||||
},
|
||||
},
|
||||
MobileSsoExchangeRequest: {
|
||||
type: 'object',
|
||||
required: ['code', 'code_verifier'],
|
||||
properties: {
|
||||
code: {
|
||||
type: 'string',
|
||||
description: 'The single-use authorization code returned to the app callback.',
|
||||
},
|
||||
code_verifier: {
|
||||
type: 'string',
|
||||
description: 'The PKCE verifier for the challenge sent to /auth/mobile/sso/start.',
|
||||
},
|
||||
},
|
||||
},
|
||||
Message: {
|
||||
type: 'object',
|
||||
properties: { message: { type: 'string', example: 'Logged out.' } },
|
||||
|
||||
Reference in New Issue
Block a user