Repository navigation
feat: add OAuth login and authenticated entity events - #206
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SchemaForge can now sign users in through OAuth providers and stream authorized entity changes directly to browser clients. Both extensions remain opt-in. This also fixes multiline hook doc comments and prevents generated hook manifests from drifting from the runtime's acton-service version.
OAuth uses audited framework providers, verified email, durable provider/subject links, signed invitations or explicit open signup, and a single-use frontend code exchange. Password and provider login share current account, tenant, principal-claim, token, timestamp, and audit behavior. Existing password hashes remain valid.
Entity events use the canonical GET projection, including Cedar, hidden and restricted fields, read hooks, relation IDs, and derived collections. Actor-owned commits preserve process ordering; bounded broadcasts disconnect slow readers without blocking writers. Live account and tenant checks close revoked streams. PostgreSQL create-intent reconciliation publishes the stored row once.
Validation was targeted locally: hook generation, OAuth/password/storage regressions, eleven stream cases, real PostgreSQL identity uniqueness and CRUD/reconciliation, OpenAPI with extensions enabled and disabled, focused cargo checks, and zero-warning runtime/CLI Clippy. The complete backend, runtime, CLI, site, and security CI suites run in this PR. PostgreSQL and SurrealDB run on separate runners with debug information and incremental artifacts disabled to bound disk use; required coverage is unchanged. Release builds include OAuth/SSE support, with configuration disabled by default.
Prepare CLI v0.48.0 and coordinated library versions, with migration notes in CHANGELOG.md, docs/oauth-login.md, and docs/events.md. Streams have no replay, cross-process fan-out, or durable outbox; clients refetch after reconnect. OAuth provisioning spans several storage operations, so an interrupted signup can require administrator repair.
Closes #200
Closes #201
Closes #202
Closes #203