Skip to content

ADR 0001: OAuth audit-only governance and secure CLI credentials

Status: Superseded — 2026-08-11

Decision

Casdoor is the independent OAuth/OIDC authorization server. Argus validates JWT access tokens locally and maps (issuer, sub) to a stable caller in one configured shared institution.

OAuth, API-key, and internal-JWT calls all use the same fail-closed governance chain: tenant isolation, permission and tool allowlist, data-license policy, public-field projection, output policy, and complete audit. The historical oauth_audit_only enum remains readable for old audit/task records but has no runtime bypass semantics.

OAuth authorization is derived only from signed access-token claims. scope (or scp) supplies permission scopes and argus_tools (or tool_whitelist) supplies the allowed Argus tools. A valid token without these authorization claims authenticates the subject but receives no tool access. The pre-registered PKCE CLI requests the explicit argus:tools:public scope; Argus maps that signed scope to the reviewed PUBLIC_OAUTH_TOOL_WHITELIST, not a wildcard over every registered tool. Release preflight verifies the complete configured scope set so deployed CLI and resource-server authorization cannot silently diverge.

The CLI adds the keyring dependency and refuses plaintext credential storage. Authorization Code + PKCE uses a fixed loopback callback and a public client.

Consequences

Casdoor establishes the authenticated identity; Argus remains the authorization, license, output-policy, and audit enforcement point. Token material and personal profile data remain excluded from Argus persistence and audit.