已开启
[Post-MVP][AUTH] Late-bind Yandex and Telegram login to one Sessionless user #172
urandon创建于  21 小时前
urandon
urandon成员
21 小时前 创建

Product-owner request 2026-10-09. Parent #29; consumes #168/#171. Explicit POST-MVP follow-up, NOT a gate for WebUI-first pilot or current Yandex login. Scheduled in the separate Product UX milestone, outside the MVP release checklist.

Goal: a user who initially signed in through Yandex or Telegram can later explicitly attach the other login identity to the same canonical Sessionless user and use either method. Keep sessions, tenant membership, own resources and audit stable; transport/provider IDs never become product identity.

Actionable scope:

  1. Reuse existing external_identities and reverse mapping plus revocable Web sessions. Define one explicit link command with exact current user/security revision and short-lived single-use server-side linking challenge bound to browser/session/selected target provider.
  2. Require fresh proof of the existing authenticated account and independent proof of the newly linked provider through its accepted adapter. Exact origin/CSRF/PKCE/state and where applicable OIDC nonce rules remain; login mode must not be confused with link mode.
  3. In one transaction require active current identity/session/membership, reject target subject already bound to another user, then attach only an unused verified external subject to the current user with a content-free audit receipt. No automatic matching by email/name/username/equal raw subject, no account merging, tenant creation or resource grants.
  4. Add unlink with fresh confirmation/revision guard, session invalidation and prevention of removing the final usable login method; race/replay/lost-response reconcile exact audited outcome without taking over an account. Distinguish local unlink from provider token revocation.
  5. Minimal settings UX for linked methods/status and actionable denial, using existing design rules. Test both initial directions, equal numeric subjects, existing-account conflict, suspended/revoked membership/session, CSRF/login-vs-link confusion, concurrent linking/unlink, stale/replay and browser refresh. Independent security/authority review + exact-head CI before merge.

No new provider catalog/passwords/sharing/account migration. Repository design/implementation remains separate future work; live OAuth app registrations, secret writes and deployments require exact rollout authority. Preserve no ambient linking and provider namespace isolation in #171 until this explicit flow is delivered.

likedislike
urandonurandon成员
21 小时前 关联了里程碑:MVP — Authenticated WebUI (#29)
urandonurandon成员
21 小时前 添加了label:securitywebui
urandonurandon成员
21 小时前 修改了issue 的描述
urandonurandon成员
21 小时前 关联了里程碑:Product UX — Chat, tenant & federation administration
urandonurandon成员
20 小时前 关联了pull request:[WEB-07a] Add Yandex OAuth login without Telegram dependency (#171)
urandonurandon成员
19 小时前 关联了pull request:[WEB-05a] Validate explicitly selected cloud Web login smoke (#173)