feat: harden runtime lifecycle and application credentials
- enforce deterministic runtime lifecycle state transitions - add live graceful-to-forced shutdown escalation - align HTTP draining and worker shutdown with global deadline - guarantee deterministic shutdown hook ordering - add secure application client IDs and one-time client secrets - hash application secrets with BLAKE3 and constant-time verification - make credential creation and rotation transactionally auditable - enforce strict client_id authentication and redirect URI validation - add SQLite and PostgreSQL credential migrations - add application credential and runtime lifecycle acceptance tests - update Dioxus application management workflows - update security and architecture documentation
This commit is contained in:
1 parent
4c697e9adf
commit
dc5417334b
26 files changed
+2477
-183
No files matched your search
@@ -0,0 +1,21 @@
|
||||
-- ── Add Application Credentials Columns & Permissions (SQLite) ────────────────
|
||||
|
||||
ALTER TABLE applications ADD COLUMN client_id TEXT;
|
||||
ALTER TABLE applications ADD COLUMN description TEXT;
|
||||
ALTER TABLE applications ADD COLUMN client_secret_hash TEXT;
|
||||
ALTER TABLE applications ADD COLUMN redirect_uris TEXT;
|
||||
ALTER TABLE applications ADD COLUMN scopes TEXT;
|
||||
|
||||
-- Backfill client_id for existing applications
|
||||
UPDATE applications SET client_id = 'nx9_app_' || replace(id, '-', '') WHERE client_id IS NULL;
|
||||
|
||||
-- Create unique index on client_id
|
||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_applications_client_id ON applications(client_id);
|
||||
|
||||
-- Seed applications:manage permission
|
||||
INSERT OR IGNORE INTO permissions (id, name, description) VALUES
|
||||
('20000000-0000-0000-0000-000000000008', 'applications:manage', 'Manage registered application credentials');
|
||||
|
||||
-- Grant permission to admin role
|
||||
INSERT OR IGNORE INTO role_permissions (role_id, permission_id) VALUES
|
||||
('10000000-0000-0000-0000-000000000001', '20000000-0000-0000-0000-000000000008');
|
||||
Reference in new issue
Block a user