128 Commits

Author SHA1 Message Date
b34475b4fb
Merge pull request #14 from mrteye/feat-webauthn-prf-task-9777533714682100655
feat(docs): Add task for WebAuthn PRF extension
2026-08-23 22:52:43 -07:00
792ed141d2
Merge pull request #15 from mrteye/feat-recovery-sss-matrix-task-4186155517714950179
Add task file for 2-of-3 SSS Wasm recovery matrix
2026-08-23 22:52:36 -07:00
efe2523307
Merge pull request #16 from mrteye/feat-audit-merkle-ledger-task-5295491276490979898
feat: Add Merkle Tree Ledger task file
2026-08-23 22:52:29 -07:00
google-labs-jules[bot]
7ae19b1033 feat(planning): add task file for RFC 6962 Merkle Tree Ledger
Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 05:52:16 +00:00
google-labs-jules[bot]
4b6001a646 Add task file for 2-of-3 SSS Wasm recovery matrix
Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 05:52:11 +00:00
google-labs-jules[bot]
dcecbd3edd feat(docs): add task for WebAuthn PRF extension
Added a new task markdown file `2026-0824.01.jul.feat.webauthn.prf-extension-1200.md` detailing the plan for integrating the WebAuthn PRF extension. It outlines the schema updates, client and server flow implementations, and progressive fallback logic as per Kanban guidelines.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 05:52:03 +00:00
4e7d6c8add docs(tasks): mark Prompt 2.1 as complete in JULES_PROMPTS.md 2026-08-23 22:37:21 -07:00
95ef596407
Merge pull request #13 from mrteye/feat-http-sigs-7822098764133354425
feat: implement RFC 9421 HTTP message signatures
2026-08-23 22:36:13 -07:00
google-labs-jules[bot]
182c789e05 feat(auth): implement RFC 9421 HTTP Message Signatures
- Added native Deno WebCrypto Ed25519 signature verification middleware for headless edge workloads.
- Integrated dual authentication path to `/api/forward-auth` processing signatures and session cookies.
- Added dual storage Admin Management routes (`/api/admin/hwk`) securely inserting directly to PostgreSQL and pushing to $O(1)$ Valkey verification set.
- Completed all quality gates checks and hermetic mocked tests successfully.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 05:36:01 +00:00
de2dcc85f7 docs(tasks): mark Prompt 2.2 as complete in JULES_PROMPTS.md 2026-08-23 21:56:57 -07:00
0ebbcf38c7 docs: format GHOST_COCKPIT_SPEC.md 2026-08-23 21:56:46 -07:00
fdcf9ded05
Merge pull request #12 from mrteye/feat-ghost-cockpit-protocol-3135824224285676341
feat(sdk): Implement Ghost Cockpit Protocol WebSocket guard helper
2026-08-23 21:54:11 -07:00
69b5edca8c docs: author practical playbook and 10 high-ROI use cases in docs/USE_CASES_AND_EFFORT.md 2026-08-23 21:54:00 -07:00
google-labs-jules[bot]
b919c66cbc feat(sdk): Implement Ghost Cockpit Protocol WebSocket guard helper
- Formalized Ghost Cockpit Protocol in docs/GHOST_COCKPIT_SPEC.md.
- Added `GhostCockpitClient` reference implementation.
- Implemented `createWebSocketGuard` in `sdk/hono.ts` to seamlessly terminate invalidated user sessions with code 1008.
- Added robust lifecycle cleanups and error checking for WebSocket frame deliveries on socket close.
- Added comprehensive integration tests in `sdk/hono.test.ts`.
- Cleaned unused imports and fixed all linting warnings.
- Moved task definition to complete.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:53:51 +00:00
e15e5a8038
Merge pull request #11 from mrteye/http-sigs-rfc9421-task-8607209458702274605
feat: add RFC 9421 task file
2026-08-23 21:41:21 -07:00
66e11afdc3 docs(tasks): format JULES_PROMPTS.md markdown tables 2026-08-23 21:41:08 -07:00
google-labs-jules[bot]
a0989a3bed Add task for RFC 9421 HTTP Message Signatures verification
Adds a detailed markdown task file in `tasks/new/` following the Kanban guidelines to outline the architectural implementation plan for RFC 9421 HTTP Message Signatures verification at edge nodes using native Deno WebCrypto.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:41:05 +00:00
e09496cf83
Merge pull request #10 from mrteye/task-ghost-cockpit-protocol-1413997499442523563
feat: draft ghost cockpit protocol task
2026-08-23 21:40:25 -07:00
google-labs-jules[bot]
d100495ead feat: draft ghost cockpit protocol task
Created the task file for formalizing the Ghost Cockpit Protocol and its corresponding WebSocket guard helper in the SDK, adhering strictly to the required guidelines.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:39:44 +00:00
731fa825f1 docs(tasks): update execution roadmap and completed statuses in JULES_PROMPTS.md 2026-08-23 21:28:15 -07:00
5db9108ecd test(server): clean up valkey stubbing in server/main.test.ts 2026-08-23 21:24:21 -07:00
8390dcac3d
Merge pull request #9 from mrteye/feat-ingress-grant-vector-injection-17171143789522307350
feat: Ingress Grant Vector Injection (/api/forward-auth)
2026-08-23 21:23:16 -07:00
google-labs-jules[bot]
8ff5090ffa feat: Implement Ingress Grant Vector Injection for ForwardAuth
- Add `domain` column to `apps` table.
- Create Valkey caching layers for app resolution by host (`auth:app_by_host:<host>`) and user grants (`auth:grants:<userId>:<appId>`) with PostgreSQL fallback in `server/auth-session.ts`.
- Update `/api/forward-auth` endpoint to resolve `X-Forwarded-Host`, enforce Default-Deny, check RBAC grants, and inject `X-Forwarded-*` scopes.
- Update relevant unit tests to cover missing and invalid scenarios with correct Mock stubs.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:23:04 +00:00
57570a0976
Merge pull request #8 from mrteye/feat-spire-ffi-argon2id-7776325516155569495
feat: Native Argon2id in spire_ffi
2026-08-23 21:20:43 -07:00
66317d2f03
Merge pull request #7 from mrteye/jul-feat-sdk-realtime-invalidation-bus-9783554891086298346
feat(sdk): add real-time invalidation event bus
2026-08-23 21:20:33 -07:00
google-labs-jules[bot]
9da28a6416 feat(spire-ffi): implement native Argon2id derivation
- Added `argon2` v0.5 dependency to `spire_ffi/Cargo.toml`
- Implemented `argon2id_derive` FFI function in `spire_ffi/src/lib.rs` with C-ABI.
- Added Deno FFI binding `deriveArgon2idKey` in `server/spire_ffi.ts` with `nonblocking: true` to prevent stalling the event loop.
- Pre-allocates output buffer on the Deno side as the standard FFI pattern.
- Included fallback mock behavior when `libspire_ffi.so` is not loaded, returning a 32-byte 0xaa filled array.
- Updated unit tests in `server/spire_ffi.test.ts` to test mock usage and successful generation.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:19:48 +00:00
google-labs-jules[bot]
3d66535889 feat: implement zero-dependency real-time event bus in AuthSdk
Added a lightweight, zero-dependency event bus to the `AuthSdk` to listen for Valkey RESP3 push invalidation events and emit them to registered listeners.
The implementation properly captures errors from synchronous and asynchronous listeners, ensuring they do not crash the primary SDK listener loop. Extracted the Valkey event processor to improve hermetic testability.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 04:19:40 +00:00
a938b8c305 docs(tasks): add Task Critique & Plan Review Template to tasks/META_PROMPT.md 2026-08-23 20:59:48 -07:00
11786de7e4
Merge pull request #6 from mrteye/feat-spire-ffi-native-argon2-task-4427490188496264791
feat(spire-ffi): task plan for native Argon2id derivation
2026-08-23 20:57:41 -07:00
4b72d491bf
Merge pull request #4 from mrteye/feat-sdk-realtime-invalidation-bus-task-2670591133327528715
docs(tasks): draft realtime invalidation bus task for SDK
2026-08-23 20:57:34 -07:00
a3e157608e
Merge pull request #5 from mrteye/feat-ingress-grant-injection-task-592912514149159076
docs: draft task file for Ingress Grant Injection
2026-08-23 20:57:28 -07:00
google-labs-jules[bot]
2b3b6f9636 feat(spire-ffi): create planning task for native Argon2id FFI
- Generated Kanban markdown file adhering to tasks/GUIDELINES.md.
- Documented requirements for SIMD, Deno FFI non-blocking bindings, and `hash-wasm` alternatives.
- Specified development/production fallback strategies.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 03:57:17 +00:00
google-labs-jules[bot]
38310f4ead docs: draft task file for Ingress Grant Injection in forward-auth
Creates a new task markdown file in `tasks/new` detailing the
architecture and implementation steps required to inject
flattened RBAC grants via Valkey caching for `/api/forward-auth`.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 03:56:04 +00:00
google-labs-jules[bot]
1f94f27b57 docs(tasks): draft realtime invalidation bus task for SDK
Creates a Kanban task file outlining the architectural plan and
implementation steps for adding a zero-dependency real-time event
bus to `@auth-yes/sdk`. This bus will listen for Valkey RESP3 push
invalidation events and emit raw token strings to registered
listeners, ensuring safe and isolated execution to prevent downstream
crashes.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 03:55:00 +00:00
google-labs-jules[bot]
2753b6b757 docs(tasks): draft realtime invalidation bus task for SDK
Creates a Kanban task file outlining the architectural plan and
implementation steps for adding a zero-dependency real-time event
bus to `@auth-yes/sdk`. This bus will listen for Valkey RESP3 push
invalidation events and emit raw token strings to registered
listeners, ensuring safe and isolated execution to prevent downstream
crashes.

Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
2026-08-24 03:54:55 +00:00
cf64161a8b docs: preserve cryptographic verification dossier in docs/VERIFY.md and expand Jules prompt library 2026-08-23 20:41:48 -07:00
31e4bd51c4 docs: add phased implementation plan and pre-configured Jules orchestrator meta-prompts 2026-08-23 20:35:14 -07:00
2684e30a23 docs: add comprehensive deep research and architecture brief for cross-ecosystem investigation 2026-08-23 20:06:55 -07:00
e81969d5a4 feat(sdk): inject scopes into context, add requireScope guard, add timeoutMs support, and document Traefik dual-router pattern 2026-08-23 19:33:35 -07:00
a85223f149 docs: generalize ONBOARDING.md into a universal, technology-agnostic integration guide 2026-08-23 19:04:57 -07:00
f2f671a386 docs: add comprehensive client application onboarding and integration guide 2026-08-23 19:01:08 -07:00
f36e237c84 fix(infra): adopt stack.env naming convention and align PostgreSQL 18 volume mount path 2026-08-23 18:50:55 -07:00
37f86f2ba7 fix(spire): maintain bootstrap token continuously until agent enrollment completes 2026-08-23 11:29:15 -07:00
1151431e5f fix(spire): fix camelCase -joinToken CLI flag in entrypoint.agent.sh 2026-08-23 11:26:40 -07:00
d1f728f834 feat(spire): add insecure_bootstrap and automatic join token generation for zero-friction agent enrollment 2026-08-23 11:12:50 -07:00
f967ba3480 feat(infra): separate Auth-Yes and SPIRE environment configurations 2026-08-23 11:05:53 -07:00
e7f01940b3 fix(spire_ffi): silence noisy cert parse error on invalid certs and add SPIFFE cert unit test 2026-08-23 10:58:40 -07:00
3e0eb7d9d7 chore: clean up deno.json tasks and unify subcommands under setup CLI 2026-08-23 10:47:36 -07:00
434ac32336 feat(infra): integrate release pipeline natively into setup.ts with rolling restart and new install guides 2026-08-23 10:45:46 -07:00
26739f4b63 feat(infra): add release script, secrets verification, and dump subcommands to setup CLI 2026-08-23 10:41:03 -07:00