Fix #370: OIDC usernames identity #373
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!373
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-370"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #370 — usernames, not emails, as the OIDC identity key.
A. Usernames as identity key:
principalFromEmail(internal/server/auth.go) returnsPrincipal{Name: <username>, Email: <email>}— derived at first login (email local-part viaauth.DeriveUsername, collision-uniquified crueber/crueber2/…, immutable, stable), stored onusers/<username>/user.json↔users/by-email/<enc>/ref.jsonalias (CAS on creation, law 4; repeat logins = 1 alias GET, law 6). Wired viaAuthService.UsernameResolver/EmailLookuphooks (law 8 — server never imports identity); nil falls back to the pure base (still no @). Session/token wires keep the email (existing sessions valid, law 5).PrincipalForNameresolves usernames via lookup, fail-closed otherwise.Leak audit: every
Principal.Namesurface now renders usernames;GET /users/{u}fillsemailonly for self;TestEmailLeakAudit+ auth-surface tests assert emails absent (deny messages, access.json, invites, rosters, org-hook titles, me/check/tokens).Migration/alias:
ValidPrincipalaccepts both spellings;matchPrincipal(pure, push-path safe) keeps rosters/access/invites/inboxes/teams resolving; grant sites bind user namespaces only viaisUserNamespace(registry-backed username or legacy email — never orgs/synthetics/unclaimed; the #346 writeless-self pin holds). Affected keys enumerated in docs/features/01 §Decisions (users/*, members, access subjects, teams, invites, issue/PR authors, notify recipients, ssh-keys; policy.json email spellings fail closed → manual migration).B. Import plumbing: owner dropdown (
allowedOwners+isValidOwnerPart) holds usernames+orgs only; username-self admission + email-owner 400 pinned (ownerbind matrix, PostValidationMatrix).C. Back-to-form moved to the done/outcome view; removed from the inline-error form.
Tests: identity 95.9%, auth 100%, server 98.3%, repoimport 95.8%, api 95.3%; -race clean; node 721 pass (2 pre-existing dist failures, same as main); gofmt/vet clean; esbuild syntax OK. No new deps.