77 lines
2.2 KiB
Markdown
77 lines
2.2 KiB
Markdown
# Simplify Authentik Auth - Tasks
|
|
|
|
## Phase 1: Remove Old Auth Code
|
|
|
|
- [ ] **Task 1.1**: Remove JWT service (`src/auth/jwt_service.py`)
|
|
- Delete file
|
|
- Remove all imports and usages
|
|
|
|
- [ ] **Task 1.2**: Remove refresh token store (`src/auth/refresh_store.py`)
|
|
- Delete file
|
|
- Remove refresh token model (`src/models/refresh_token.py`)
|
|
- Remove table in Alembic migration
|
|
|
|
- [ ] **Task 1.3**: Remove complex OIDC logic
|
|
- Simplify `src/auth/oidc.py` to basic OAuth2 flow
|
|
- Remove JWKS fetching
|
|
- Remove token verification
|
|
|
|
- [ ] **Task 1.4**: Clean up auth dependencies
|
|
- Remove `python-jose` from dependencies if no longer needed
|
|
- Update `pyproject.toml`
|
|
|
|
## Phase 2: Implement Session Auth
|
|
|
|
- [ ] **Task 2.1**: Create session service (`src/auth/session.py`)
|
|
- Session cookie creation/signing
|
|
- Session cookie parsing/verification
|
|
- Session expiry handling
|
|
|
|
- [ ] **Task 2.2**: Update auth endpoints (`src/api/auth.py`)
|
|
- Simplify login endpoint
|
|
- Update callback to create session instead of JWT
|
|
- Update /me to read from session
|
|
- Simplify logout
|
|
|
|
- [ ] **Task 2.3**: Update auth middleware
|
|
- Replace JWT middleware with session middleware
|
|
- Load user from database based on session
|
|
|
|
- [ ] **Task 2.4**: Update configuration
|
|
- Remove JWT config
|
|
- Add SESSION_SECRET and SESSION_TTL_HOURS
|
|
- Update .env.example
|
|
- Update docker-compose configs
|
|
|
|
## Phase 3: Update Frontend
|
|
|
|
- [ ] **Task 3.1**: Remove JWT handling from frontend
|
|
- Delete token refresh logic
|
|
- Remove access token storage
|
|
|
|
- [ ] **Task 3.2**: Update auth API client
|
|
- Remove refresh endpoint calls
|
|
- Simplify auth state management
|
|
|
|
- [ ] **Task 3.3**: Update protected route logic
|
|
- Check session cookie instead of JWT
|
|
- Simpler auth state
|
|
|
|
## Phase 4: Testing & Cleanup
|
|
|
|
- [ ] **Task 4.1**: Update auth tests
|
|
- Rewrite tests for new session-based flow
|
|
- Remove JWT-specific tests
|
|
- Add session validation tests
|
|
|
|
- [ ] **Task 4.2**: Run quality gates
|
|
- ruff check
|
|
- mypy
|
|
- pytest
|
|
- frontend typecheck + lint + build
|
|
|
|
- [ ] **Task 4.3**: Documentation
|
|
- Update README with new auth flow
|
|
- Update deployment docs
|
|
- Document configuration changes
|