Skip to content

feat: add local and Bubble identity services - #237

Draft
Yuge Zhang (ultmaster) wants to merge 1 commit into
microsoft:mainfrom
ultmaster:feat/228-identity-service
Draft

Yuge Zhang (ultmaster) wants to merge 1 commit into
microsoft:mainfrom
ultmaster:feat/228-identity-service

Conversation

@ultmaster

Copy link
Copy Markdown
Collaborator

Depends on #236. This draft is stacked on its Node 24 commit and should merge afterward. Implements the first identity-only phase of #228; the broader integration issue remains open.

Huabu currently ties owner access to loopback/Basic Auth. Introduce a Huabu-owned IdentityService so request admission and owner checks use one interface with or without Bubble. The local provider supplies a stable synthetic owner and preserves configured Basic Auth. The Bubble HTTP adapter validates Bearer credentials through /v1/auth/whoami, preserves principal IDs, and requires an explicit Bubble system-owner grant for the existing shared Workspace.

GET /api/identity exposes the safe principal projection before Workspace activation. Bubble failures never fall back to local identity; requests revalidate credentials, and long-lived HTTP responses revalidate every 30 seconds. The Agentlet connection token remains a separate non-owner machine identity. Configuration and deployment-security documentation cover both modes.

Draft scope and follow-up:

  • This adapter connects to an existing Bubble server containing the identity/revocation changes from octostaff/umbrella@48b7d727 or later. It does not add an unpublished Bubble dependency.
  • Bubble mode currently supports Bearer API clients. Browser login/session handling and embedding Bubble remain follow-up work.
  • Conversations, storage, and agent execution remain unchanged. Per-Workspace/Space authorization is outside this phase; ordinary Bubble application access is initially restricted to system owners.

Validation on the combined Node 24 branch:

  • Frozen-lockfile install, lint (0 errors; 322 existing warnings), formatting, typecheck, full production build, and server bundles passed.
  • All 4,701 unit tests passed, including 2,042 server tests covering both providers, owner admission, machine credentials, revocation, redirects, malformed upstream responses, and streaming shutdown.
  • A live smoke test using the real Huabu server and local Bubble runtime passed: local identity, shared principal, explicit owner grant, readiness, account disablement, and clean shutdown.
  • i18n, Agent Team skills, and license-header checks passed.

Storage-container/browser suites and desktop installer builds were not rerun for this identity-only draft.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant