Files
headquarter/openspec/changes/archive/2025-05-17-oauth-traefik-integration/specs/auth-oauth/spec.md
T
Fusion c722cab86c chore: archive completed user-profile change
Archive user-profile change to openspec/changes/archive/
All tasks complete, specs already synced to main specs directory.
2026-05-18 09:45:36 +02:00

1.2 KiB

MODIFIED Requirements

Requirement: OAuth2/OIDC Flow

The system SHALL support OAuth2/OIDC authentication via Authentik with fully configurable endpoints.

Scenario: User login

  • GIVEN a user clicks the login button
  • WHEN the frontend redirects to Authentik authorization endpoint
  • THEN the redirect URI SHALL be constructed from environment-configured domains
  • AND the Authentik authorize URL SHALL be read from environment variables

Scenario: Token exchange and validation

  • GIVEN Authentik has redirected with authorization code
  • WHEN the callback endpoint receives the code
  • THEN it exchanges the code for provider tokens at the configured token URL
  • AND verifies token signature using the configured JWKS URL
  • AND validates the issuer and audience from environment configuration

Requirement: Session Security

The system SHALL protect sessions using httpOnly cookies with environment-aware secure defaults.

  • GIVEN successful authentication behind Traefik with HTTPS
  • WHEN cookies are set
  • THEN access_token cookie SHALL be httpOnly
  • AND access_token cookie SHALL have Secure flag based on environment
  • AND access_token cookie SHALL have SameSite based on environment