feat: add local and Bubble identity services - #237
Draft
Yuge Zhang (ultmaster) wants to merge 1 commit into
Draft
Yuge Zhang (ultmaster) wants to merge 1 commit into
Yuge Zhang (ultmaster) wants to merge 1 commit into
Conversation
Yuge Zhang (ultmaster)
force-pushed
the
feat/228-identity-service
branch
from
September 24, 2026 08:05
7390def to
aabfef0
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #236. This draft is stacked on its Node 24 commit and should merge afterward. Implements the first identity-only phase of #228; the broader integration issue remains open.
Huabu currently ties owner access to loopback/Basic Auth. Introduce a Huabu-owned
IdentityServiceso request admission and owner checks use one interface with or without Bubble. The local provider supplies a stable synthetic owner and preserves configured Basic Auth. The Bubble HTTP adapter validates Bearer credentials through/v1/auth/whoami, preserves principal IDs, and requires an explicit Bubble system-owner grant for the existing shared Workspace.GET /api/identityexposes the safe principal projection before Workspace activation. Bubble failures never fall back to local identity; requests revalidate credentials, and long-lived HTTP responses revalidate every 30 seconds. The Agentlet connection token remains a separate non-owner machine identity. Configuration and deployment-security documentation cover both modes.Draft scope and follow-up:
octostaff/umbrella@48b7d727or later. It does not add an unpublished Bubble dependency.Validation on the combined Node 24 branch:
Storage-container/browser suites and desktop installer builds were not rerun for this identity-only draft.