Skip to content

U2c: verify Access and Slack human proofs for linking #2387

Description

@justinhelmer

Parent: #2371. Follows merged U2a decision #2383 and the atomic store/intent foundation #2386. This slice proves two human subjects but does not expose linking to users.

Deliverable: add a trusted Access human-proof projection from the existing verified application JWT, retaining verified issuer, audience, subject, expiry and human authentication kind; reject service-token, token/none strategy, view-as, email header or decoded but unverified claims as linking proof. Add a separate Sign in with Slack OpenID Connect confidential-client adapter. The authorization-code callback uses one-time state/nonce and the intent's browser/session binding, exact redirect URI, signed ID token issuer/audience/time/nonce, and signed workspace/team and user subject. Its identity key is issuer + team + subject; matching email, a bot token and requested team hints confer nothing.

Keep the provider boundary replaceable with a deterministic test implementation. Protect callback query values from logs, referrers, caches, run events and audit payloads; store validated identity metadata only, never authorization codes, JWTs or refresh tokens. Align callback transport with the live discovery pinned in proposed record 0081 and fail closed on a protocol mismatch. Do not add production Slack scopes, redirect registration, client secret or live configuration in this PR.

Proof: living-spec rows and focused positive/negative tests for Access issuer/audience/expiry/key rotation and human/service shape; Slack signature/key/issuer/audience/nonce/state/team/user-sub mismatch; replay, account switch, expired intent, wrong browser and callback crash. A valid proof passes only exact identity metadata to #2386's transaction seam. No account link or person-derived authorization is reachable from live ingress.

Boundary: no FE consent flow, public link/unlink route, production credential provisioning, email-bridge retirement or enablement. Those need later U2 reviews and a person-approved cutover.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions