Skip to content

U2d: stage browser consent for verified account linking #2395

Description

@justinhelmer

Parent: #2371. Follows the offline Access/Slack proof adapters in #2387. Align the browser surface with the UI refactor without exposing account linking yet.

Deliverable: a local consent ceremony behind a disabled entry point. Show the verified Access account and signed Slack account/workspace before a protected final POST. Revalidate the initiating Access tuple, audience, browser/session binding, intent state and unchanged deadline at callback and consent. Bind the one-time callback to the stored intent; never use email, display name, a requested team hint or a client-supplied person id to select a person. Pass only validated identity metadata to #2386's atomic transaction. Use a same-origin CSRF-protected initiation/final POST and a clean URL after callback.

Proof: living-spec rows and focused tests for explicit consent, cancelled/expired intent, wrong browser, account switch, callback replay/crash, duplicate final POST, response loss and no second transaction. Show that codes, JWTs, raw callback query, secrets and refresh tokens cannot reach logs, referrers, caches, run events or audits. Include a replaceable fake provider and UI fixtures for both themes. A successful ceremony must still require a later release gate before any live link route is reachable.

Boundary: no production Slack scopes, redirect registration, client secret, link/unlink enablement, person-derived authorization, history migration or email-bridge retirement. Record 0081 remains proposed; this is staged implementation, not activation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions