Login com gov.br (OIDC) — registro, backend, frontend #1
Labels
No labels
area/api
area/auth
area/dashboard
area/db
area/frontend
area/llm
area/scrapers
meta
priority/critical
priority/high
priority/low
priority/medium
type/bug
type/feature
type/infra
type/refactor
type/security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
soberania-brasileira/digital#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Contexto
Plataforma hoje é HTML estático servido por nginx. Não há backend de sessão. Login com gov.br abre as portas para features que dependem de identidade verificada (reportar contratos suspeitos, alertas, painel pessoal de auditor).
Fase 0 — externo (pré-requisito)
client_id+client_secretno ambiente staging (sso.staging.acesso.gov.br)https://soberaniadigital.org.br/auth/callbackFase 1 — backend
api/auth.py(FastAPI + Authlib) com/auth/login,/auth/callback,/auth/me,/auth/logoutusers(id,cpfhashed,nome,email,govbr_nivelbronze/prata/ouro,foto_url,created_at,last_login_at,role)itsdangerous) ou JWT — TTL 24h, refresh transparenteFase 2 — frontend
index.html(header)$store.auth.user)/auth/logoutlinkFase 3 — operação
soberania-api.service+ env file/etc/soberania/secrets.envcarregandoGOVBR_CLIENT_ID,GOVBR_CLIENT_SECRET,SESSION_SECRET,PGPASSWORD/auth/*e/api/*→ uvicorn :8081Riscos / decisões
Documentação