Skip to content

feat(reborn): wire product auth composition seam - #3878

Merged
henrypark133 merged 2 commits into
reborn-integrationfrom
feat/reborn-auth-composition
May 23, 2026
Merged

henrypark133 merged 2 commits into
reborn-integrationfrom
feat/reborn-auth-composition

Conversation

@hanakannzashi

Copy link
Copy Markdown
Contributor

Summary

  • Adds RebornProductAuthServices as the single Reborn composition seam for product auth flows, secure manual-token interactions, credential setup/accounts, provider exchange, and cleanup.
  • Wires the seam into build_reborn_services readiness: local-dev gets the in-memory Reborn auth implementation, while production only reports product-auth ready when a Reborn-native bundle is explicitly injected.
  • Adds caller-level composition coverage for manual-token submit redaction and updates architecture guardrails/docs to keep [Reborn] Step 2: Wire Reborn-native product auth and secrets composition #3811 separate from [Reborn] Add approval/auth interaction services #3094 blocked-run gate resolution.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Closes #3811
Related #3289
Stacked on #3865 (feat/reborn-auth-product-contracts). After #3865 lands, this PR should be retargeted to reborn-integration.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo build
  • Relevant tests pass: cargo test -p ironclaw_reborn_composition --locked, cargo test -p ironclaw_auth --locked, cargo test -p ironclaw_architecture reborn_product_auth_contract_stays_reborn_native --locked, cargo test -p ironclaw_architecture reborn_crate_dependency_boundaries_hold --locked, cargo test -p ironclaw_architecture no_substrate_crate_depends_on_composition_root --locked
  • cargo test --features integration if database-backed or integration behavior changed
  • Manual testing: Not applicable; composition and contract behavior are covered by tests.
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Additional validation:

  • cargo clippy -p ironclaw_reborn_composition --all-targets -- -D warnings
  • cargo check -p ironclaw_reborn_composition --features libsql --locked
  • cargo check -p ironclaw_reborn_composition --features postgres --locked
  • git diff --check

Security Impact

Yes. This adds the Reborn-native product-auth composition seam. It keeps callers on trait-shaped product-auth ports and documents that production must inject durable Reborn auth services explicitly instead of falling back to V1 routes, V1 pending maps, V1 ExtensionManager, V1 secret stores, or route-local raw HTTP clients. No production OAuth route, listener, raw provider transport, durable secret storage, token material handling, runtime credential injection, or database schema is added in this slice.

Database Impact

None. This wires composition/readiness and tests only; durable product-auth storage remains future substrate work.

Blast Radius

Limited to ironclaw_reborn_composition, the product-auth contract docs, and architecture guardrails. Existing V1 auth behavior is untouched. Local-dev now reports product-auth readiness through the in-memory Reborn auth implementation; production reports it only when explicitly injected.

Rollback Plan

Revert this PR to remove the composition bundle, readiness flag, docs, and guardrail updates. No data migration or runtime cleanup is required.

Review Follow-Through

Reviewer judgment requested on the exact composition surface and readiness semantics. #3094 remains separate: blocked run-state approval/auth gate listing, user decisions, and trusted resume should consume this auth boundary rather than adding a second auth model.


Review track: C

@github-actions github-actions Bot added scope: docs Documentation scope: dependencies Dependency updates size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: experienced 6-19 merged PRs labels May 22, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces RebornProductAuthServices as a centralized composition seam for authentication within the ironclaw_reborn_composition crate. Key changes include the integration of the ironclaw_auth dependency, updates to the service factory and build inputs to support auth services across local-dev and production profiles, and the addition of readiness tracking for the auth facade. Furthermore, architectural tests were added to enforce dependency boundaries, and a new test ensures that sensitive tokens are redacted during manual-token submission. Review feedback focused on documenting the restrictive trait bounds in the from_shared constructor, maintaining consistency in readiness flag logic across different build profiles, and improving error messaging in test helpers by using .expect().

Comment thread crates/ironclaw_reborn_composition/src/auth.rs
Comment thread crates/ironclaw_reborn_composition/src/factory.rs Outdated
Comment thread crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs Outdated
@github-actions github-actions Bot added size: L 200-499 changed lines and removed size: M 50-199 changed lines labels May 22, 2026
Base automatically changed from feat/reborn-auth-product-contracts to reborn-integration May 22, 2026 23:24
@henrypark133
henrypark133 force-pushed the feat/reborn-auth-composition branch from 67a43ef to d70a260 Compare May 22, 2026 23:34

@henrypark133 henrypark133 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review (multi-agent)

Intent: Wire RebornProductAuthServices composition seam into service readiness with coverage, docs, and architecture guardrail updates.

Stats: 5 findings (from 5 raw, 5 after dedup) across 4 files. Reviewers run: security, bugs, performance, tests, conventions, design. Reviewers failed: none. Body-only: 0

Tests

  1. Medium — RebornProductAuthServices::new public constructor has no direct test (crates/ironclaw_reborn_composition/src/auth.rs:46-62, confidence 75) — anchor: crates/ironclaw_reborn_composition/src/auth.rs:46
    The public constructor taking six separate trait-object Arcs is never called directly in any test. The doc comment states production should prefer this over from_shared, but no test exercises it with distinct mock implementations.

  2. Medium — RebornProductAuthServices::from_shared has no test with a custom multi-trait impl (crates/ironclaw_reborn_composition/src/auth.rs:70-95, confidence 75) — anchor: crates/ironclaw_reborn_composition/src/auth.rs:70
    from_shared is only exercised indirectly via local_dev_in_memory() with InMemoryAuthProductServices. No test verifies that from_shared correctly clones the Arc for each trait slot when given a custom type implementing all six traits.

  3. Medium — RebornBuildInput::with_product_auth_services builder method has no test (crates/ironclaw_reborn_composition/src/input.rs:171-176, confidence 75) — anchor: crates/ironclaw_reborn_composition/src/input.rs:171
    The public builder method for injecting custom product-auth services into production builds is never exercised. No test verifies that a production build with injected services reports product_auth readiness as true and returns the injected bundle.

  4. Low — Production build readiness with product_auth=false is not asserted in existing tests (crates/ironclaw_reborn_composition/src/factory.rs:519-527, confidence 50) — anchor: crates/ironclaw_reborn_composition/src/factory.rs:522
    Existing production tests do not assert that readiness.facades.product_auth is false when no auth services are injected, nor that services.product_auth is None.

  5. Low — collect_forbidden_reborn_auth_file_uses helper has no dedicated test (crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs:2262-2283, confidence 50) — anchor: crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs:2262
    The new helper uses .expect() on file read and iterates forbidden patterns. No test verifies it correctly detects a violation when auth.rs contains a forbidden pattern, or that it handles a missing file path gracefully.

Comment thread crates/ironclaw_reborn_composition/src/auth.rs
Comment thread crates/ironclaw_reborn_composition/src/auth.rs
Comment thread crates/ironclaw_reborn_composition/src/input.rs
Comment thread crates/ironclaw_reborn_composition/src/factory.rs
Comment thread crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs
@henrypark133
henrypark133 force-pushed the feat/reborn-auth-composition branch from d70a260 to 78094bf Compare May 23, 2026 00:04
@henrypark133
henrypark133 merged commit 1436e68 into reborn-integration May 23, 2026
15 checks passed
@henrypark133
henrypark133 deleted the feat/reborn-auth-composition branch May 23, 2026 00:13
ilblackdragon added a commit that referenced this pull request May 26, 2026
…budgets-followups

Conflict in crates/ironclaw_reborn_composition/src/lib.rs: kept both
budget (HEAD #3841 follow-ups) and auth (origin #3878 product auth seam)
module declarations and pub re-exports.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
* feat(reborn): wire product auth composition seam

* fix(reborn): address auth composition review gaps
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: experienced 6-19 merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates scope: docs Documentation size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants