Specify and prototype a secure Android account authentication contract
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- android, go
- Domain
- authentication, backend-api-design, mobile-dev, security
Research direction
Start with the prerequisite #77, then read internal/web/handler/auth.go, internal/session/, and internal/auth/turnstile.go. Compare the browser-session and browser-to-app authorization options, mapping trust boundaries, expiration, revocation, logout, and request binding. Done means an approved wire contract and automated synthetic cases rejecting replay, wrong bindings, and stale callbacks, with production integration deferred.
Written by the indexing model from the issue text.
Description
Roadmap: #76
Problem
Current login uses TOTP, Turnstile, and an HttpOnly wave_session cookie. The app needs an explicit account-session design before adding authenticated screens.
Scope
Produce a narrowly scoped protocol decision and isolated test prototype for app sign-in, session expiration, and logout. Compare reusing the browser session with an explicit browser-to-app authorization exchange; choose the design appropriate to #77. This is not a request to replace current website authentication.
Done
- Map trust boundaries, challenge verification, session issuance/storage, cancellation, expiration, revocation, and logout.
- If a return exchange is selected, specify short-lived single-use codes bound to the initiating app request; keep reusable credentials out of redirect URLs.
- Demonstrate rejection of replay, wrong destination/request binding, and stale callbacks with automated synthetic cases.
- Explain the cookie/browser or native-credential boundary without weakening Turnstile or existing origin checks.
- Record the approved wire contract and split production server/client integration into follow-up issues.
Start: internal/web/handler/auth.go, internal/session/, and internal/auth/turnstile.go. No real credentials or production login experiments.
Prerequisites: #77.
- Dominant language
- Go
- Stars
- 1
- Forks
- 7
- Avg merge
- 6h 25m
- Merged PRs (30d)
- 18
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from wavefnd/wave-platform
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
wavefnd/wave-platform#139 ·
Maintainers usually reply within 1 day
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulty 2/5 Half a day Newbie friendliness 88/100
wavefnd/wave-platform#137 ·
Maintainers usually reply within 1 day
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
wavefnd/wave-platform#136 ·
Maintainers usually reply within 1 day
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulty 1/5 Under an hour Newbie friendliness 94/100
wavefnd/wave-platform#135 ·
Maintainers usually reply within 1 day
-
bug difficulty: beginner documentation good first issue help wanted localization
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
wavefnd/wave-platform#133 ·
Maintainers usually reply within 1 day
All issues in wavefnd/wave-platform
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
NVIDIA/k8s-device-plugin#2076 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
area/release kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
kubernetes-sigs/kueue#16455 · 1 comment ·
Maintainers usually reply within 1 day