Skip to content

feat(react-native-kratos): add native authentication lifecycle - #3

Open
TorinAsakura wants to merge 29 commits into
masterfrom
feat/kratos-auth-lifecycle
Open

TorinAsakura wants to merge 29 commits into
masterfrom
feat/kratos-auth-lifecycle

Conversation

@TorinAsakura

@TorinAsakura TorinAsakura commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Task

How to test

Main scenario

  1. Context: the provider's initial SecureStore read fails; syncSession() then reads credential A and starts toSession, whose response is held.
    Action: call explicit logout before validation finishes, make its first remote revocation fail, retry logout on the same provider, and release the late validation response.
    Expected result: the known credential is revoked, local auth and storage are cleared, the retry completes remote work, and the late response cannot authenticate A. Before the fix, the store performed no revocation and the provider did not expose the known credential.
  2. Context: legacy user_session JSON is being validated, or an old validation is pending while account B is accepted.
    Action: hold validation until its SDK call has actually started; inspect storage before success, or reject the old call with 401 after B is persisted.
    Expected result: migration waits for successful validation, and the old response cannot delete or replace B.

Additional scenario

  1. Context: account A is confirmed, overlapping replacements are pending, or Kratos temporarily fails.
    Action: fail a later persistence write, synchronize during acceptance, and retry synchronization after a temporary failure.
    Expected result: the last persisted credential remains authoritative, synchronization waits for acceptance, and temporary failure retains the confirmed public auth state. Local clear remains distinct from explicit logout; account switching does not automatically revoke another account's session.
  2. Context: issue [Package] Kratos React Native #1 requires only the current consuming application's Expo 56 / React Native 0.85 / React 19 password integration.
    Action: build and pack the candidate, typecheck its public declarations and run clean-cache Metro exports using the current consumer's installed auth-runtime dependency versions.
    Expected result: package output resolves through registry dependencies without a private dependency substitution, custom resolver or consumer change. This is compatibility proof, not adoption in Caily.
  3. Context: the exact candidate runs in Expo Go 56.0.4 on the existing Android 16 / API 36 / arm64 emulator, against the existing non-production Yggdrasil stand, Kratos 1.3.0.
    Action: submit password registration and login through the public native wrappers, restart the application, inspect SecureStore without displaying its value, synchronize, log out, and repeat synchronization while the test Kratos service is stopped and after recovery. Disable only the controlled test session and synchronize again.
    Expected result: credentials persist and restore through server validation, explicit logout revokes the captured session, temporary failure preserves the confirmed session and credential while rejecting, recovery clears the error, and a confirmed inactive session clears auth and storage.

Proof

  • Published fixing commit: eb692b0813348561270eb2bae64455201b8c403d. Normal hooks passed and its GPG signature verified. No published history was rewritten.
  • Current head: a0342050324a9c3c4d901a498d61ac15bc9ae3bf; base master at b1c497fcc24b71922abfa4e4ca24f41c18c3bfc7. The logout, scope, workflow-correction and test-cleanup commits are signed, normal hooks passed, and the writer is clean. Published history was not rewritten.
  • Scope commit: bd6b8669a1a5accb828012596a4ace10d82c0e29. Removed the native browser exchange/callback implementation, its six tests, web AsyncStorage fallback and its test, and excluded peers/development versions. Kept the shared React Kratos exports, password flow implementation and official shared errors. README is an English application-developer integration guide.
  • Workflow ownership correction: b37960054948a204e42ca66c4e284489aa4c705d removes the one-line direct caller override added in 92b5f43ad43b5921be4b80620072b8010148d210. .github/workflows/checks.yaml is rendered by the Terraform-owned react_native_actions module in the ATLS infrastructure repository, so the PR must not own that file. The workflow content is again the Terraform-declared form; no shared workflow, Terraform, Raijin dependency, permissions or service was changed here. The forthcoming Raijin major is a separate change.
  • Test cleanup: a0342050324a9c3c4d901a498d61ac15bc9ae3bf removes two store-level duplicates. Public AuthProvider cases still cover local clear versus explicit logout, and pending restoration followed by logout, retry and a late validation result. The remaining 403 AAL behavior was not changed because it is a separate semantic decision.
  • Exact-head repository-managed checks: unit 25/25 across three files, typecheck, lint and prepack build passed at a034205. Temporarily restoring the two previous logout/restoration production statements with the same strengthened tests produced two failures: explicit logout did not revoke the known restoring token, and the provider omitted that token while validation was pending. Restoring the fix returned 34/34 before excluded browser/web coverage was removed.
  • AI finding 4140068644 has two claims. Automatic revocation of A merely because account B supersedes restoration conflicts with issue [Package] Kratos React Native #1 and is not implemented. Explicit logout missing credential A after storage has already returned it is valid and is fixed by the commit above. Observable store and mounted-provider checks reach the actual pending SDK operation, cover revocation/retry and discard its late result. outdated is not used as proof.
  • The AI thread was resolved natively and exact readback confirmed isResolved: true. Per the existing instruction, the known HTTP 422 reply failure was not retried; the fixing evidence is recorded here. The user's review 5359924081 remains pending and was not submitted, discarded, replied to or resolved.
  • Package archive freshly built and packed at current head has SHA-256 986c0a330b34a10168b363e44e1d2168a3152ec4ba577bca3c222ff9b61ea8b8. It contains only README.md, CHANGELOG.md, package.json and dist/**, including usable ESM exports and declarations. No exchange helper is present. Byte-for-byte comparison confirmed that it is identical to the a034205, b379600 and 92b5f43 archives, and to the archive actually tested on Android at bd6b866. Unit 25/25, typecheck, lint and build/prepack were executed again at a034205; byte identity does not substitute for device acceptance.
  • Package-output checks passed in the existing isolated fixtures for that same archive: the recommended Expo 56.0.23 / RN 0.85.3 / React 19.2.3 fixture passed strict TypeScript, expo install --check and clean-cache Android export after unused adapter peers were removed. The read-only Caily consumer's installed Expo 56.0.9 / RN 0.85.3 / React 19.2.3 / RN Web 0.21.2 / SecureStore 56.0.4 / WebBrowser 56.0.5 versions were independently read back and reproduced in its existing fixture: strict TypeScript and clean-cache Android/iOS/web exports passed. Its expo install --check separately reports the consumer's existing Expo and WebBrowser patch drift; the consumer was not changed. This reproduces the auth-runtime graph, not every product feature or dependency.
  • In both fixtures, the only file: dependency is the candidate archive. Shared React Kratos 0.1.0, Ory client 26.2.0 and external runtime dependencies resolved from the public registry. No product repository, foreign writer, private-path dependency, package extension or custom resolver was changed.
  • The earlier exact-head GitHub run passed: Checks, Lint, TypeCheck, Test:Unit, Test:Integration and Release. That run used atls/shared workflow commit 632f9e2c201d5aa6ea0188c6810e915c016ab843 with yarn checks run.
  • A subsequent run of the previous bd6b866 head failed before the validation commands: Checks failure. The existing caller follows atls/shared master; this run selected shared workflow commit 42773a0116128c7e32034e6bb4f06886d396a43e and its intentional Raijin v2 default yarn check --verify. This RN repository still uses released Raijin 0.7.0, which rejected that v2 option with Unsupported option name ("--verify"). The supported caller input in 92b5f43 preserves this repository's existing command without reverting shared or prematurely migrating RN to v2; no old-head manual rerun was used.
  • The 36788692779 CI run passed at historical head 92b5f43 with the direct override. At b379600, run 36797040888 fails before repository validation commands: the Terraform-managed caller selects shared 42773a0116128c7e32034e6bb4f06886d396a43e, whose default is yarn check --verify, and released Raijin 0.7.0 rejects --verify. The a034205 test-only cleanup does not change that infrastructure-owned version skew. The PR intentionally does not reintroduce a direct workflow override to hide it. Maintained gh pr checks --required separately reports no configured required checks: not_applicable, not a reconstructed required set.
  • Current-candidate Android observations: registration A authenticated and persisted a token matching SecureStore; force-stop/reopen restored A and synchronization resolved; explicit logout cleared auth/storage and left zero active A sessions; password login created an active A session. While the test Kratos service was stopped, synchronization rejected but retained confirmed A and its matching stored credential; after recovery it resolved and cleared the error. Disabling only that controlled A session followed by synchronization cleared auth/storage and left zero active A sessions.
  • The actual Android/device run above is anchored to bd6b866, not relabeled as a new a034205 execution. The a034205 test-only cleanup does not touch package sources, manifests, lock/PnP or packaged bytes. Its byte-identical package makes the archived Android observations applicable to the package artifact without restarting the emulator or backend; this is not a new device-acceptance claim.
  • Android account switching accepted B and persisted its matching credential while A and B each retained one active server session. Logout B with Kratos unavailable rejected but cleared local auth/storage; after recovery both server sessions were still active. Retrying logout on the same mounted Provider resolved and left B with zero active sessions, without revoking A. Logging in B again and calling local clear removed local auth/storage while A and B each remained active: local clear did not perform server logout.
  • Cleanup disabled only the remaining controlled A/B test sessions, with zero active sessions read back for both; identities and database were retained. The existing stand was restored with readiness HTTP 200, its existing database healthy and mailslurper running. No backend copy or snapshot was made. Expo Go required reopening the same project after its first cold intent landed at the launcher; restoration was observed after force-stop/reopen, not inferred. This is emulator/Expo Go proof, not a standalone APK claim. Legacy migration, storage failures and controlled asynchronous races are covered by unit/mounted-provider tests, not Android fault injection.
  • Stand/runtime boundary: only the existing non-production Yggdrasil Compose project was used; the real server reports Kratos v1.3.0, build 0a49fd05245f179501b117163cd574786f287fe8; the real device client is SDK 26.2.0. Login and registration were device actions through the candidate's public wrappers and SecureStore, not host-side SDK substitutes. Admin reads and deactivation were confined to the controlled test identities/sessions. No local Docker stand, new server, callback/configuration change, production-data change or server upgrade was performed. Endpoints, credentials and identity/session payloads are omitted.
  • Local cumulative self-review completed at 92b5f43ad43b5921be4b80620072b8010148d210 with no new adapter-code findings. At a034205, the new diff was separately checked: it removes only the two duplicated store scenarios and leaves the package artifact byte-identical. Both user pending-review threads remain preserved; no provider review is claimed for this head.
  • Independent read-only technical review by the coordinating agent completed at 92b5f43ad43b5921be4b80620072b8010148d210 against issue [Package] Kratos React Native #1, with no new actionable adapter-code findings. It remains evidence for unchanged adapter code, not a provider review of a034205. This is a technical review, not a submitted provider review or human approval; the user's pending review remains untouched.
  • iOS device verification is deferred. Package publication, consumer adoption, infrastructure deployment and merge are not claimed. Automatic Codex review quota did not substitute for or block the completed local and independent read-only technical reviews.

@TorinAsakura TorinAsakura changed the title feat(kratos): add native auth lifecycle feat(react-native-kratos): add native authentication lifecycle Sep 29, 2026
@TorinAsakura
TorinAsakura marked this pull request as ready for review September 29, 2026 23:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T01:52:52.670991Z 4a26947 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bda7075118

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/session-token.storage.ts Outdated
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: caf9b05c4b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4206181883

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6fb25e3d92

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth.provider.tsx Outdated
Comment thread packages/react-native-kratos/src/index.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5300c0bf08

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/session-token.storage.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4dcfa088e4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6efcc3808

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 05a84d16a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4a269472fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@TorinAsakura

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Package] Kratos React Native

1 participant