Skip to content

Add isolated Business authorization and revocable sessions - #1003

Closed
sridharkalaibala wants to merge 6 commits into
mainfrom
codex/business-access
Closed

sridharkalaibala wants to merge 6 commits into
mainfrom
codex/business-access

Conversation

@sridharkalaibala

@sridharkalaibala sridharkalaibala commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Business needs an owner/manager session that cannot sell or enroll a till. Add a separate tenant-side browser consent flow with S256 proof binding, browser-session nonce/origin checks, atomic one-use exchange, hashed opaque sessions, and current account/branch/permission validation on every request.

Rotation preserves absolute expiry; device listing/revocation is scoped to the caller. Discovery explicitly reports prepared reporting as unavailable. Existing POS routes reject Business tokens. The tenant also consumes proof-bound grants from the companion Cloud account-service/gateway changes.

Validation: six integration tests pass locally against disposable MongoDB and real HTTP routes; the 34 route/readme tests, ESLint, formatting, generated API docs and attribution checks pass. Existing CI API, desktop, packaging and database checks pass. The test fixture documents its tested custom CSRF protection for the static scanner. No CI jobs/triggers are added and no production deployment is included.

Comment thread api/src/routes/business-access.routes.js Fixed
Comment thread api/tests/business-access.integration.cjs Fixed
Comment thread api/tests/business-access.integration.cjs Fixed
Comment thread api/tests/business-access.integration.cjs Fixed
Comment thread api/tests/business-access.integration.cjs Dismissed
@sridharkalaibala

Copy link
Copy Markdown
Contributor Author

The complete Business companion stack, including this change, is integrated into develop through #1023. All checks, including CodeQL, passed before merge. Closing this superseded stacked PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants