Skip to content

feat: add OAuth login and authenticated entity events - #206

Merged
rrrodzilla merged 13 commits into
mainfrom
fix/issues-200-203
Oct 6, 2026
Merged

rrrodzilla merged 13 commits into
mainfrom
fix/issues-200-203

Conversation

@rrrodzilla

@rrrodzilla rrrodzilla commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

SchemaForge can now sign users in through OAuth providers and stream authorized entity changes directly to browser clients. Both extensions remain opt-in. This also fixes multiline hook doc comments and prevents generated hook manifests from drifting from the runtime's acton-service version.

OAuth uses audited framework providers, verified email, durable provider/subject links, signed invitations or explicit open signup, and a single-use frontend code exchange. Password and provider login share current account, tenant, principal-claim, token, timestamp, and audit behavior. Existing password hashes remain valid.

Entity events use the canonical GET projection, including Cedar, hidden and restricted fields, read hooks, relation IDs, and derived collections. Actor-owned commits preserve process ordering; bounded broadcasts disconnect slow readers without blocking writers. Live account and tenant checks close revoked streams. PostgreSQL create-intent reconciliation publishes the stored row once.

Validation was targeted locally: hook generation, OAuth/password/storage regressions, eleven stream cases, real PostgreSQL identity uniqueness and CRUD/reconciliation, OpenAPI with extensions enabled and disabled, focused cargo checks, and zero-warning runtime/CLI Clippy. The complete backend, runtime, CLI, site, and security CI suites run in this PR. PostgreSQL and SurrealDB run on separate runners with debug information and incremental artifacts disabled to bound disk use; required coverage is unchanged. Release builds include OAuth/SSE support, with configuration disabled by default.

Prepare CLI v0.48.0 and coordinated library versions, with migration notes in CHANGELOG.md, docs/oauth-login.md, and docs/events.md. Streams have no replay, cross-process fan-out, or durable outbox; clients refetch after reconnect. OAuth provisioning spans several storage operations, so an interrupted signup can require administrator repair.

Closes #200
Closes #201
Closes #202
Closes #203

@rrrodzilla
rrrodzilla merged commit dfc9914 into main Oct 6, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment