Skip to content

feat(auth): password-policy & session settings — live, enforced (P0 security) - #2011

Merged
os-zhuang merged 1 commit into
mainfrom
feat/auth-security-settings-p0
Jun 17, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
feat/auth-security-settings-p0

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

P0 base-settings, item 3 of 3. Per the agreed scope, this extends the existing auth manifest with the security-policy keys that are genuinely enforced today — rather than standing up a security namespace full of non-functional toggles (IP allowlist / SSO / SCIM / rate-limit), which would be false surface and trip the platform's own liveness gate.

What's added (all live)

Existing auth manifest (global scope), new groups:

  • Password policy — password_min_length (default 8), password_max_length (default 128). better-auth enforces these on sign-up and password reset.
  • Sessions — session_expiry_days (default 7, absolute lifetime), session_refresh_days (default 1, refresh threshold).

How they take effect (existing tested path)

They ride AuthPlugin.bindAuthSettings → AuthManager.applyConfigPatch:

  • Read from the settings service on kernel:ready and re-applied live via settings.subscribe('auth').
  • applyConfigPatch deep-merges into config and nulls the cached better-auth instance, so the next request rebuilds with the new policy.
  • Days → seconds for session.{expiresIn,updateAge}. Unset (source: 'default') and malformed/non-positive values are ignored so the provider default holds.

Deliberately out of scope (no enforcement exists → NOT declared)

MFA-required, IP allowlist, SSO/SAML, SCIM, API rate limits, password complexity/rotation/history. These are real features to build, not settings toggles. Recorded so the gap is explicit.

Tests

  • auth.manifest.test.ts — new number fields parse with bounds/defaults; password_policy/sessions groups present.
  • auth-plugin.test.ts — bindAuthSettings applies length bounds + session lifetime (days→seconds); ignores default-source and malformed/non-positive values.
  • Suites green: service-settings 124, plugin-auth 120. DTS builds clean.
  • en + zh-CN translations.

P0 complete

  1. ✅ localization (feat(settings): localization settings — platform timezone/language/formats (ADR-0053 Phase 2) (#1928) #2006). 2. ✅ company (feat(settings): company settings — legal organization identity (P0) #2010). 3. this PR auth security policy.

🤖 Generated with Claude Code

…ecurity)

Extends the existing `auth` settings manifest (global scope) with the security
keys that are genuinely enforced today, instead of a new `security` namespace
full of non-functional toggles (false surface).

- Password policy: password_min_length (8), password_max_length (128) —
  enforced by better-auth on sign-up / password reset.
- Sessions: session_expiry_days (7), session_refresh_days (1).

Rides the existing AuthPlugin.bindAuthSettings → AuthManager.applyConfigPatch
path (read on kernel:ready, re-applied live via settings.subscribe('auth'),
which invalidates the cached better-auth instance). Days → seconds for
session.{expiresIn,updateAge}; unset/malformed values ignored so the provider
default holds. en + zh-CN translations.

Out of scope (no enforcement → not declared): MFA-required, IP allowlist,
SSO/SAML, SCIM, API rate limits, password complexity/rotation/history.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
spec Ready Ready Preview, Comment Jun 17, 2026 7:11am

Request Review

@github-actions github-actions Bot added documentation Improvements or additions to documentation tests tooling labels Jun 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/plugin-auth, packages/services.

14 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/concepts/implementation-status.mdx (via @objectstack/plugin-auth)
  • content/docs/concepts/packages.mdx (via @objectstack/plugin-auth)
  • content/docs/getting-started/cli.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/auth-sso.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/authentication.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/kernel-services.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/packages.mdx (via @objectstack/plugin-auth, packages/services)
  • content/docs/guides/plugins.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/production-readiness.mdx (via @objectstack/plugin-auth)
  • content/docs/guides/runtime-services/audit-service.mdx (via packages/services)
  • content/docs/guides/runtime-services/index.mdx (via packages/services)
  • content/docs/guides/runtime-services/settings-service.mdx (via packages/services)
  • content/docs/protocol/objectos/i18n-standard.mdx (via packages/services)
  • content/docs/releases/v9.mdx (via @objectstack/plugin-auth)

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

This branch was successfully deployed

1 active deployment
Preview — fdb5f3b3 Deployed Jun 17, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/m tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant