feat(react-native-kratos): add native authentication lifecycle - #3
TorinAsakura wants to merge 29 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bda7075118
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: caf9b05c4b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4206181883
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6fb25e3d92
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5300c0bf08
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4dcfa088e4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e6efcc3808
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 05a84d16a1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4a269472fc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Task
How to test
Main scenario
syncSession()then reads credential A and startstoSession, whose response is held.Action: call explicit logout before validation finishes, make its first remote revocation fail, retry logout on the same provider, and release the late validation response.
Expected result: the known credential is revoked, local auth and storage are cleared, the retry completes remote work, and the late response cannot authenticate A. Before the fix, the store performed no revocation and the provider did not expose the known credential.
user_sessionJSON is being validated, or an old validation is pending while account B is accepted.Action: hold validation until its SDK call has actually started; inspect storage before success, or reject the old call with 401 after B is persisted.
Expected result: migration waits for successful validation, and the old response cannot delete or replace B.
Additional scenario
Action: fail a later persistence write, synchronize during acceptance, and retry synchronization after a temporary failure.
Expected result: the last persisted credential remains authoritative, synchronization waits for acceptance, and temporary failure retains the confirmed public auth state. Local clear remains distinct from explicit logout; account switching does not automatically revoke another account's session.
Action: build and pack the candidate, typecheck its public declarations and run clean-cache Metro exports using the current consumer's installed auth-runtime dependency versions.
Expected result: package output resolves through registry dependencies without a private dependency substitution, custom resolver or consumer change. This is compatibility proof, not adoption in Caily.
Action: submit password registration and login through the public native wrappers, restart the application, inspect SecureStore without displaying its value, synchronize, log out, and repeat synchronization while the test Kratos service is stopped and after recovery. Disable only the controlled test session and synchronize again.
Expected result: credentials persist and restore through server validation, explicit logout revokes the captured session, temporary failure preserves the confirmed session and credential while rejecting, recovery clears the error, and a confirmed inactive session clears auth and storage.
Proof
a0342050324a9c3c4d901a498d61ac15bc9ae3bf; basemasteratb1c497fcc24b71922abfa4e4ca24f41c18c3bfc7. The logout, scope, workflow-correction and test-cleanup commits are signed, normal hooks passed, and the writer is clean. Published history was not rewritten..github/workflows/checks.yamlis rendered by the Terraform-ownedreact_native_actionsmodule in the ATLS infrastructure repository, so the PR must not own that file. The workflow content is again the Terraform-declared form; no shared workflow, Terraform, Raijin dependency, permissions or service was changed here. The forthcoming Raijin major is a separate change.AuthProvidercases still cover local clear versus explicit logout, and pending restoration followed by logout, retry and a late validation result. The remaining403AAL behavior was not changed because it is a separate semantic decision.outdatedis not used as proof.isResolved: true. Per the existing instruction, the known HTTP 422 reply failure was not retried; the fixing evidence is recorded here. The user's review5359924081remains pending and was not submitted, discarded, replied to or resolved.986c0a330b34a10168b363e44e1d2168a3152ec4ba577bca3c222ff9b61ea8b8. It contains onlyREADME.md,CHANGELOG.md,package.jsonanddist/**, including usable ESM exports and declarations. No exchange helper is present. Byte-for-byte comparison confirmed that it is identical to the a034205, b379600 and 92b5f43 archives, and to the archive actually tested on Android at bd6b866. Unit 25/25, typecheck, lint and build/prepack were executed again at a034205; byte identity does not substitute for device acceptance.expo install --checkand clean-cache Android export after unused adapter peers were removed. The read-only Caily consumer's installed Expo 56.0.9 / RN 0.85.3 / React 19.2.3 / RN Web 0.21.2 / SecureStore 56.0.4 / WebBrowser 56.0.5 versions were independently read back and reproduced in its existing fixture: strict TypeScript and clean-cache Android/iOS/web exports passed. Itsexpo install --checkseparately reports the consumer's existing Expo and WebBrowser patch drift; the consumer was not changed. This reproduces the auth-runtime graph, not every product feature or dependency.file:dependency is the candidate archive. Shared React Kratos 0.1.0, Ory client 26.2.0 and external runtime dependencies resolved from the public registry. No product repository, foreign writer, private-path dependency, package extension or custom resolver was changed.atls/sharedworkflow commit632f9e2c201d5aa6ea0188c6810e915c016ab843withyarn checks run.atls/sharedmaster; this run selected shared workflow commit42773a0116128c7e32034e6bb4f06886d396a43eand its intentional Raijin v2 defaultyarn check --verify. This RN repository still uses released Raijin 0.7.0, which rejected that v2 option withUnsupported option name ("--verify"). The supported caller input in 92b5f43 preserves this repository's existing command without reverting shared or prematurely migrating RN to v2; no old-head manual rerun was used.42773a0116128c7e32034e6bb4f06886d396a43e, whose default isyarn check --verify, and released Raijin 0.7.0 rejects--verify. The a034205 test-only cleanup does not change that infrastructure-owned version skew. The PR intentionally does not reintroduce a direct workflow override to hide it. Maintainedgh pr checks --requiredseparately reports no configured required checks:not_applicable, not a reconstructed required set.v1.3.0, build0a49fd05245f179501b117163cd574786f287fe8; the real device client is SDK 26.2.0. Login and registration were device actions through the candidate's public wrappers and SecureStore, not host-side SDK substitutes. Admin reads and deactivation were confined to the controlled test identities/sessions. No local Docker stand, new server, callback/configuration change, production-data change or server upgrade was performed. Endpoints, credentials and identity/session payloads are omitted.92b5f43ad43b5921be4b80620072b8010148d210with no new adapter-code findings. At a034205, the new diff was separately checked: it removes only the two duplicated store scenarios and leaves the package artifact byte-identical. Both user pending-review threads remain preserved; no provider review is claimed for this head.92b5f43ad43b5921be4b80620072b8010148d210against issue [Package] Kratos React Native #1, with no new actionable adapter-code findings. It remains evidence for unchanged adapter code, not a provider review of a034205. This is a technical review, not a submitted provider review or human approval; the user's pending review remains untouched.