Files
headquarter/openspec/changes/oauth-traefik-integration/specs/auth-oauth/spec.md
T
Fusion 577b052c05 feat: implement user profile management and oauth/traefik integration
User Profile (US-004):
- Add authenticated profile endpoints (GET/PUT /users/me)
- Add avatar upload with file validation (PNG/JPEG, max 2MB)
- Create frontend profile page with edit form and avatar upload
- Update app shell to link to profile page

OAuth/Traefik Integration:
- Externalize all Authentik URLs to environment variables
- Add domain configuration (API_DOMAIN, WEB_DOMAIN, AUTHENTIK_DOMAIN)
- Create docker-compose.traefik.yml for reverse proxy deployment
- Update OAuth redirect/callback URLs to use configured domains
- Add VITE_APP_URL for frontend public URL configuration

Quality gates: pytest (50 passed), ruff, mypy, npm test (12 passed), typecheck, lint, build
2026-05-17 23:17:10 +02:00

1.2 KiB

MODIFIED Requirements

Requirement: OAuth2/OIDC Flow

The system SHALL support OAuth2/OIDC authentication via Authentik with fully configurable endpoints.

Scenario: User login

  • GIVEN a user clicks the login button
  • WHEN the frontend redirects to Authentik authorization endpoint
  • THEN the redirect URI SHALL be constructed from environment-configured domains
  • AND the Authentik authorize URL SHALL be read from environment variables

Scenario: Token exchange and validation

  • GIVEN Authentik has redirected with authorization code
  • WHEN the callback endpoint receives the code
  • THEN it exchanges the code for provider tokens at the configured token URL
  • AND verifies token signature using the configured JWKS URL
  • AND validates the issuer and audience from environment configuration

Requirement: Session Security

The system SHALL protect sessions using httpOnly cookies with environment-aware secure defaults.

  • GIVEN successful authentication behind Traefik with HTTPS
  • WHEN cookies are set
  • THEN access_token cookie SHALL be httpOnly
  • AND access_token cookie SHALL have Secure flag based on environment
  • AND access_token cookie SHALL have SameSite based on environment