diff --git a/src/arts/connection/DESIGN_CONN.md b/src/arts/connection/DESIGN_CONN.md index db6cc47..d3c03a6 100644 --- a/src/arts/connection/DESIGN_CONN.md +++ b/src/arts/connection/DESIGN_CONN.md @@ -501,7 +501,7 @@ const Connections = App.createActiveConnections(); or, once integrated: ```ts -App.Connections.connection('main'); +App.connections.connection('main'); ``` Do **not** put this under: @@ -1516,7 +1516,7 @@ const Main = Connections.createConnection('main', { ### 20.2 Why factory on App -Use an App factory, not a generic `App.Connections` baked into `ActiveApp` by default. +Use an App factory, not a generic `App.connections` baked into `ActiveApp` by default. Recommended: diff --git a/src/arts/orca/README.md b/src/arts/orca/README.md index 1e70f6f..b0c9ddd 100644 --- a/src/arts/orca/README.md +++ b/src/arts/orca/README.md @@ -230,8 +230,8 @@ Orca.onEvent(APP_EVENT_USER_IDENTITY_CHANGED, { - politica de error - timers -La accion es la que decide llamar a `App.cache`, `App.Permissions`, -`App.Connections` o cualquier otro servicio. +La accion es la que decide llamar a `App.cache`, `App.perm`, +`App.connections` o cualquier otro servicio. ## Setup Tipado *(roadmap v2)* @@ -1017,8 +1017,8 @@ App.Orchestration.onEvent(APP_EVENT_USER_IDENTITY_CHANGED, { onError: ORCA_ON_ERROR_ABORT_RUN, action: async (payload) => { await App.cache.clearActorScope(payload.previousActorId); - App.Permissions.invalidate(); - await App.Connections.reauthenticateAll(); + App.perm.invalidate(); + await App.connections.reauthenticateAll(); return orcaSuccess(); } }); @@ -1117,7 +1117,7 @@ Orca.onEvent(APP_EVENT_USER_IDENTITY_CHANGED, { provides: [ORCA_TOKEN_PERMISSIONS_INVALIDATED], onError: ORCA_ON_ERROR_ABORT_STAGE, action: async () => { - await App.Permissions.invalidate(); + await App.perm.invalidate(); return orcaSuccess({ emits: [ORCA_TOKEN_PERMISSIONS_INVALIDATED] }); } }); @@ -1129,7 +1129,7 @@ Orca.onEvent(APP_EVENT_USER_IDENTITY_CHANGED, { abortOn: [ORCA_TOKEN_CACHE_ERROR], onError: ORCA_ON_ERROR_CONTINUE, action: async () => { - await App.Connections.reauthenticateAll(); + await App.connections.reauthenticateAll(); return orcaSuccess({ emits: [ORCA_TOKEN_CONNECTIONS_REAUTHENTICATED] }); } }); diff --git a/src/libs/auth/consts.ts b/src/libs/auth/consts.ts index b4681d7..957999b 100644 --- a/src/libs/auth/consts.ts +++ b/src/libs/auth/consts.ts @@ -6,6 +6,11 @@ export const AUTH_AAPP_KEYS = { ACTIVE: 'auth.active' } as const; +/** + * Routes the built-in auth handler (`createAuthHttpHandlers`) dispatches. + * Every entry here has an active server-side path; the public client + * (`ActiveAuth`) drives them through this list. + */ export const AUTH_ROUTE_PATHS = { BASE: '/api/auth', CURRENT: '/api/auth/current', @@ -18,12 +23,28 @@ export const AUTH_ROUTE_PATHS = { EMAIL_VERIFY_COMPLETE: '/api/auth/email/verify/complete', PASSWORD_RESET_REQUEST: '/api/auth/password/reset/request', PASSWORD_RESET_COMPLETE: '/api/auth/password/reset/complete', + DEVICES: '/api/auth/devices', + DEVICE_REVOKE: '/api/auth/devices/revoke' +} as const; + +/** + * Reserved paths for OAuth, MFA and WebAuthn flows. The built-in + * handler does NOT dispatch these — engine/server code for them is + * either partial or out of scope for the current release. Apps that + * implement those flows must wire their own SvelteKit handlers at the + * paths declared here so a future built-in handler stays + * URL-compatible. + * + * Marking them experimental, instead of leaving them next to the + * supported routes, prevents the situation the codex audit flagged: + * `ActiveAuth` consumers calling URLs that silently 404 because the + * generic dispatcher never routed them. + */ +export const AUTH_EXPERIMENTAL_ROUTE_PATHS = { OAUTH_START: '/api/auth/oauth/start', OAUTH_CALLBACK: '/api/auth/oauth/callback', MFA_CHALLENGE: '/api/auth/mfa/challenge', MFA_VERIFY: '/api/auth/mfa/verify', - DEVICES: '/api/auth/devices', - DEVICE_REVOKE: '/api/auth/devices/revoke', WEBAUTHN_REGISTER_OPTIONS: '/api/auth/webauthn/register/options', WEBAUTHN_REGISTER_VERIFY: '/api/auth/webauthn/register/verify', WEBAUTHN_AUTH_OPTIONS: '/api/auth/webauthn/auth/options', diff --git a/src/web/routes/active/_data/nav.ts b/src/web/routes/active/_data/nav.ts index a41ce1d..3e99602 100644 --- a/src/web/routes/active/_data/nav.ts +++ b/src/web/routes/active/_data/nav.ts @@ -3,7 +3,7 @@ * Single source of truth for the left rail and breadcrumbs. * * `label` is the public name a developer sees in the API - * (`App.Session`, `App.storage`, …). `alias` is the path-alias + * (`App.session`, `App.storage`, …). `alias` is the path-alias * used to import the artifact (`$session`, `$storage`, …) and matches * the folder name under `src/arts/`. */