Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions crates/ironclaw_auth/CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# ironclaw_auth Guardrails

- Own product-facing auth vocabulary and fake services only.
- Exception: `ProviderBackedCredentialAccountService` may live here because refresh serialization and status projection belong at the `CredentialAccountService` boundary, while raw provider/token material stays behind `AuthProviderClient` and secret boundaries.
- Keep Reborn auth code independent from V1 route handlers, V1 pending state, V1 extension manager authority, and V1 secret-store implementation details.
- Serializable records may contain hashes, ids, handles, statuses, and redacted metadata. They must not contain raw OAuth state, PKCE verifiers, authorization codes, tokens, secret values, provider response bodies, backend internals, or host paths.
- Raw OAuth callback material may appear only in non-serializable one-shot inputs to provider exchange boundaries.
Expand Down
4 changes: 2 additions & 2 deletions crates/ironclaw_auth/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -23,10 +23,10 @@ serde_json = "1"
sha2 = "0.10"
subtle = "2"
thiserror = "2"
tokio = { version = "1", features = ["rt"] }
tokio = { version = "1", features = ["rt", "sync"] }
url = "2"
uuid = { version = "1", features = ["v4", "serde"] }

[dev-dependencies]
serde_json = "1"
tokio = { version = "1", features = ["macros", "rt"] }
tokio = { version = "1", features = ["macros", "rt", "sync"] }
Loading
Loading