Skip to content

LISTENER-ID-01 — Google and Apple Listener identity boundary #196

Description

@nicoechaniz

Objective

Provide isolated Harmonic Beacon Listener identity and sessions for registered Free and canonical membership without granting event capabilities.

Current state — accepted

  • Google Authorization Code flow is deployed and human-accepted on canonical Listener, including logout/re-login.
  • Replacement Google OAuth client/secret was deployed under LISTENER-SEC — Rotate exposed Google OAuth client secret #328; previous credentials were revoked.
  • State/PKCE, replay and negative authorization remain fail-closed.
  • Provider subject plus opaque canonical account is authoritative; email never grants access or Founder.
  • Listener sessions grant no event tickets, staff, LiveKit, Myth Bot or Proyección del Mito authority.
  • Universal email magic link LISTENER-ID-02 — Passwordless email magic-link fallback #217 is deployed through the isolated mail sidecar and accepted in a real browser: delivery → one-use callback → email-only Free session → logout.
  • Facebook, implicit cross-provider linking and password/test login remain absent from public Listener.
  • Apple is hidden and explicitly deferred until Apple Developer Program access, Team ID, App ID, Services ID, Key ID, private .p8/client-secret JWT, callbacks and 2FA are available. Apple does not block launch.

Acceptance

  • Google state/PKCE, callback, logout, expiry and negative authorization tests.
  • Real canonical Google login/logout/re-login.
  • Controlled Google client-secret rotation and callback regression.
  • No persisted OAuth token, session IP or user-agent; no cross-product capabilities.
  • Founder continuity belongs to current canonical paid authority, not email/provider.
  • Missing external-provider configuration fails closed without breaking Google.
  • Magic-link request/delivery boundary deployed without modifying event identity/runtime.
  • Real-browser magic-link callback→email-only Listener→Free→logout.
  • Apple requirements documented and provider hidden until configured.

No identity slice changes event auth, audio, payments or live.harmonicbeacon.com.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

early-birdsEarlyBirds isolated Listener and 24/7 stream lane

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions