ROADMAP — Centralized Social Login — GitHub/Google via SystemAuth¶
Initiative: INIT-SYSTEMFORGE-005
Repository: github.com/plexusone/systemforge
Builds the central "log in with GitHub/Google" capability that downstream
relying-party applications have long referenced as RMI-SYSTEMFORGE-001 but
which was never specced or built here (the roadmaps start at
RMI-SYSTEMFORGE-003; the OAuth server PRD deferred social login as "handled
separately"). Full rationale and the architecture decision — IdP-centralized in
SystemAuth, not a per-app library — are in ADR-002; RMI titles below are
summaries.
These RMIs are defined but not yet claimed or scheduled — they are the design of record for a later execution session. Commits implementing an item will carry the trailer
Refs: RMI-SYSTEMFORGE-<NNN>; none exist yet. Phase status derives from member-RMI status.
The identity substrate is ready: sf_principal_id is defined once in the shared
identity/ent/mixin.PrincipalMixin (ADR-001) and relying parties link upstream
identities to it. What this initiative adds is the login surface and a
single sanctioned place to build it.
Phase 1 — SystemAuth Social Login (core)¶
Theme: One place speaks to GitHub/Google; SystemAuth owns the login
- [ ]
RMI-SYSTEMFORGE-075Consolidate the two duplicate social-login primitive packages (session/oauth,identity/oauthclient) into one sanctioned package; retire the dead one - [ ]
RMI-SYSTEMFORGE-001Mount GitHub/Google login on the SystemAuth server: login-start + callback routes,Principalupsert keyed by provider subject with verified-email linking fallback,__Host-sf_loginsession establishment - Depends on:
RMI-SYSTEMFORGE-075 - [ ]
RMI-SYSTEMFORGE-076Harden the login flow: allowlist-validated post-login redirect with no token in the URL, real refresh-token rotation (reuse detection, absolute expiry), real logout with session + token revocation - Depends on:
RMI-SYSTEMFORGE-001
Phase 2 — Relying-Party Federation Contract¶
Theme: Consumers federate; nobody reimplements the callback
- [ ]
RMI-SYSTEMFORGE-077Serve/oauth/userinfo(advertised in discovery but unmounted) so the relying-party callback has a stable profile endpoint - Depends on:
RMI-SYSTEMFORGE-001 - [ ]
RMI-SYSTEMFORGE-081Reusable relying-party OIDC-client callback + middleware (sub →sf_principal_idfind-or-create, verified-email linking) and the/bff/*cookie-session surface the shared frontend expects; programmatic clients keep bearer/API-key access - Depends on:
RMI-SYSTEMFORGE-001 - Depends on:
RMI-SYSTEMFORGE-077
Phase 3 — Consumer Convergence & Lock¶
Theme: Every consumer onto central login; prevent per-app drift
Downstream consumers retire app-local GitHub/Google login and adopt the
relying-party federation contract (RMI-SYSTEMFORGE-081), linking by
sf_principal_id. These per-consumer items are tracked in the initiative and
intentionally not enumerated here, matching INIT-SYSTEMFORGE-004.
- [ ]
RMI-SYSTEMFORGE-078CI gate + conformance: block new direct github.com/google.com OAuth wiring outside the sanctioned package; conformance check that relying parties key bysf_principal_id - Depends on:
RMI-SYSTEMFORGE-081