Skip to content

fix(identity): pass managed browser bridge credentials and HTTPS trust - #107

Merged
adrianwebb merged 1 commit into
stagingfrom
codex/identity-admin-runtime-wiring
Sep 10, 2026
Merged

adrianwebb merged 1 commit into
stagingfrom
codex/identity-admin-runtime-wiring

Conversation

@adrianwebb

Copy link
Copy Markdown
Contributor

Outcome

Pass the protected manager environment into the published Admin container, explicitly declare browser-bridge configuration and its sealed workload credential, and route public API/Identity authorities through verified local HTTPS. No login form or browser-secret fallback.

Work authority

Contributor mode (select one):

  • Human-authored
  • Agent-assisted under human authority
  • Agent-authored under human authority

Plan

Implement bounded live-cutover wiring, verify exact-head Actions, merge staging, publish exact artifacts, then activate with a coordinated restore point. Keep auto-updater paused during serial cutover.

Changes and commits

7e6d8c8: Pass the protected manager environment into the published Admin container, explicitly declare browser-bridge configuration and its sealed workload credential, and route public API/Identity authorities through verified local HTTPS. No login form or browser-secret fallback.

Verification

Component generation contract test passes, including exact runtime digest, protected environment input, required workload key descriptor and read-only CA mount. Existing application artifact remains unchanged.

  • I ran the narrowest relevant package verification and documented any checks that could not be run.

Risk and rollback

Before activation, revert this source change. After account/schema cutover, use the coordinated application and shared PostgreSQL restore point; never restart an old authentication writer on incompatible migrated data. No purge/bootstrap reinstall. No secrets or machine-specific configuration committed.

Completion summary

Implementation and targeted tests complete; required Actions and actual managed acceptance are pending. This PR does not claim that browser login is cut over.

AGPL committer authorization

Use the base-owned provider-authenticated author check where applicable; no spoofing or bypass.

Submission checklist

  • The change is bounded to the stated work item and target repository.
  • Exact base and head refs are recorded and the branch is ready for review.
  • Verification and compatibility evidence are recorded above.
  • No plaintext secrets, credentials, machine state, or unrelated residue are included.
  • Plan, status, commits, and completion summary form a complete durable record.
  • Rollback or recovery steps are documented and executable.

@adrianwebb
adrianwebb merged commit 499b3e3 into staging Sep 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant