Skip to content

Harden session boundary behavior - #11

Merged
nicodes merged 2 commits into
mainfrom
issue-155-behavior
Sep 13, 2026
Merged

nicodes merged 2 commits into
mainfrom
issue-155-behavior

Conversation

@nicodes

@nicodes nicodes commented Sep 12, 2026 •

Copy link
Copy Markdown
Member

Summary

  • replace permissive JWT decoding with strict, bounded, explicitly unverified metadata and typed expiry outcomes
  • default sessions and Web client IDs to memory; provide explicit sessionStorage opt-in and caller-injected native credential persistence
  • make migration explicit and nondestructive, enforce write/readback checks, and correct the nonexistent README client-ID API
  • prepare package version 0.0.2

Tracks aviorstudio/fieldsofrevik#155 without auto-closing the cross-repository issue before publication verification.

Acceptance evidence

  • Explicit unverified JWT contract: JwtModule.inspect_unverified() validates three canonical base64url segments, UTF-8, JSON objects, algorithm policy, typed claims, exact integer bounds, and a 64 KiB cap. Metadata and expiry results remain trusted = false; tests reached TEST_REACHED:jwt_module_test:20.
  • Safe session contract: memory is the non-persistent default; native persistence requires NativeCredentialAdapter; Web persistence requires explicit WEB_SESSION_STORAGE. JSON payloads are acyclic/lossless and capped at 1 MiB; tests reached TEST_REACHED:session_store_module_test:26.
  • Atomic writes/logout/migration: native writes require adapter atomic replacement plus exact readback; tests cover failed writes preserving the old value, corrupt readback, clear/readback, and successful/failed migration retaining the plaintext source.
  • Client IDs: native retains OS.get_unique_id() and Web uses cryptographic process-memory IDs by default with explicit tab persistence. JavaScript APIs are invoked through JavaScriptBridge.get_interface(...).call(...), including quoted/newline storage-key coverage; native tests reached TEST_REACHED:client_id_module_test:4.
  • Installed package paths: the exact ZIP passed closed-manifest verification, Linux editor enable/restart/smoke/disable/restart (PACKAGE_LIFECYCLE_REACHED:enable-restart-smoke-disable-restart), and packaged Web smoke (WEB_TEST_REACHED:packaged-addon-smoke). Local ZIP SHA-256: ddd012067fbb4a3060f1a560096daca2f01a485c65d6a8acb755e3901db5eaf0.
  • Browser verification: personally run with playwright-cli 0.1.18 against the Godot 4.7.2 Web export; 0 console errors, visible PASS, and direct assertions confirmed both escaped sessionStorage keys and values.

Packaged Web behavior PASS

Local verification

Godot: 4.7.2.stable.official.ed1daf0bf. Playwright CLI: 0.1.18.

python3 scripts/package_addon.py build dist/@aviorstudio_gd-supabase.zip
python3 scripts/package_addon.py verify dist/@aviorstudio_gd-supabase.zip
shellcheck tests/test.sh tests/run_godot_case.sh tests/gate_controls.sh tests/package_controls.sh
GODOT_BIN=/tmp/opencode/godot-4.7.2/Godot_v4.7.2-stable_linux.x86_64 ./tests/gate_controls.sh
GODOT_BIN=/tmp/opencode/godot-4.7.2/Godot_v4.7.2-stable_linux.x86_64 ./tests/test.sh
GODOT_BIN=/tmp/opencode/godot-4.7.2/Godot_v4.7.2-stable_linux.x86_64 ./tests/package_controls.sh dist/@aviorstudio_gd-supabase.zip
npm ci
npm run test:web
git diff --check

All passed. Gate-control error output is deliberate negative-control evidence followed by CONTROL_FAILED_AS_EXPECTED and CONTROL_RESTORED_PASS:pass.

Exact-head CI

  • Green run: https://github.com/aviorstudio/gd-supabase/actions/runs/34729226189
  • Verified head: 1ed6a5fc3f21d5e00a19f0b74e0a16ea2ee055de
  • Artifact: gate-evidence-1ed6a5fc3f21d5e00a19f0b74e0a16ea2ee055de (10309241726)
  • Artifact container digest: sha256:ed6a0b366e7f9acaa89a3375726fd6701178341e2152dd8ebbd896fb3794ef80
  • Downloaded CI package SHA-256: ddd012067fbb4a3060f1a560096daca2f01a485c65d6a8acb755e3901db5eaf0, equal to the locally tested package; closed-manifest verification passed again after download.
  • CI Web screenshot SHA-256: d21bcf23c965ab281b72670ae3e0b1f65300e1158329735df0b9d72cb3a531e3.

No review requested or awaited (Team No Review).

@nicodes
nicodes added this pull request to stack #12 September 12, 2026 23:44
Base automatically changed from issue-155-gate to main September 12, 2026 23:45
@nicodes nicodes changed the title Record session boundary decisions Harden session boundary behavior Sep 13, 2026
@nicodes
nicodes merged commit cddcabd into main Sep 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant