Repository navigation
Conversation
ADR-015 proposes that the web app sign a five-minute RS256 JWT for the session's identity and exchange it at /.sts, replacing the server-driven Ory Hydra authorization-code flow (four to six sequential calls through the Ory admin API) on the credential path. The proxy trusts the app's issuer as a person issuer with its own audience, per ADR-009's per-issuer audiences, and fetches the app's JWKS through its existing cache. It amends ADR-004's identity sources for interactive web users. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
Claude finished @alukach's task in 16s —— View job ✅ No blocking issues — safe to merge. Docs-only ADR. The claims I checked are internally consistent: the "five to seven calls" figure matches the "four to six Ory calls plus Non-blocking notes
Simplify (ponytail)
💰 Estimated review cost: $0.11 · 0m16s · 4 turns |
|
🚀 Latest commit deployed to https://source-data-proxy-pr-249.source-coop.workers.dev
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Proposes ADR-015. The web app would sign a five-minute RS256 JWT for the session's Ory identity and exchange it at
/.sts. That replaces the server-driven Hydra authorization-code flow ADR-004 describes, which costs four to six sequential calls through the Ory admin API before every web mint. The proxy would trust the app's issuer as a person issuer, with its own audience, under ADR-009's per-issuer audience rule, and fetch the app's JWKS through the cache it already has.It amends ADR-004's "Identity Sources in Use — Interactive web users". The amendment note on ADR-004 itself is left until this is accepted.
Why now
Edit Mode in source.coop is slow, and most of the wait is this chain. source.coop#636 removes what the app can remove on its own: it reuses credentials across toggles, starts the mint when the menu opens, and drops a duplicate whoami. The first mint each hour still pays for every Hydra call. A review of that work across performance, security and OAuth practice concluded that the remaining latency, and the ADR-004 "become any user" admin-API cost, both come from not using a grant the proxy can verify directly.
How it relates to earlier ADRs
subto the Source API with its own short-lived JWT; this is the same trust in the opposite direction.expvs an editable record). Neither applies to a five-minute token that is never stored.issprovides that.Numbering
#219, an older draft, also adds an
adrs/015-*andadrs/016-*. Its service-accounts ADR has since merged as 014, so whichever lands second renumbers.Testing
Docs only. Claims about existing behavior were checked against
adrs/onmainand source.coop'ssrc/lib/actions/proxy-credentials.ts.🤖 Generated with Claude Code