Description:
Implement a challenge–response login where solvers sign a server-issued Stellar transaction challenge (SEP-10 compatible) and receive a short-lived JWT used for REST and WS authentication.
Problem Statement & Context:
Solver actions are authenticated per-request with message signatures, and WS connections are anonymous. There is no session concept, which prevents per-solver WS channels, capability filtering, and scoped rate limits.
Scope & Acceptance Criteria:
GET /api/v1/auth/challenge?account= and POST /api/v1/auth/token per SEP-10 (home domain, web_auth_domain, nonce, 5-min time bounds).
- JWT (EdDSA) with
sub, role: solver|user|admin, 15-min expiry; refresh via re-challenge.
- WS accepts the token during handshake (subprotocol or first message) and binds identity to the connection.
- Existing signed-message endpoints keep working (backward compatible).
- Out of scope: user wallets login UX.
Implementation Guidelines:
- Key Files/Modules: new
src/auth/ module, src/intents/intents.gateway.ts, src/common/stellar-signature.ts.
- Design/Architecture: Use
WebAuth helpers from @stellar/stellar-sdk; JWT signing key separate from Soroban signer.
- Edge Cases/Constraints: Multisig accounts (threshold checks); challenge replay prevention with nonce store.
- Testing: Full SEP-10 conformance tests incl. multisig and expired challenges.
Definition of "Done": Common DoD; docs/solver-onboarding.md updated.
Resources:
Common Definition of "Done" (applies in addition to the criteria above):
- Code written, tested, and documented (TSDoc on public APIs, README/runbook/ADR updates where behaviour changes).
- All acceptance criteria met;
npm run lint, npm run typecheck, npm test, npm run test:e2e pass in CI.
- PR follows
.github/PULL_REQUEST_TEMPLATE, uses a Conventional Commit title (enforced by commitlint), includes test output / metrics screenshots, and references the issue.
- New env vars are added to
.env.example variants and src/config/env.validation.ts (the check:env-drift script must pass).
- Reviewed and approved by at least one CODEOWNER.
Description:
Implement a challenge–response login where solvers sign a server-issued Stellar transaction challenge (SEP-10 compatible) and receive a short-lived JWT used for REST and WS authentication.
Problem Statement & Context:
Solver actions are authenticated per-request with message signatures, and WS connections are anonymous. There is no session concept, which prevents per-solver WS channels, capability filtering, and scoped rate limits.
Scope & Acceptance Criteria:
GET /api/v1/auth/challenge?account=andPOST /api/v1/auth/tokenper SEP-10 (home domain, web_auth_domain, nonce, 5-min time bounds).sub,role: solver|user|admin, 15-min expiry; refresh via re-challenge.Implementation Guidelines:
src/auth/module,src/intents/intents.gateway.ts,src/common/stellar-signature.ts.WebAuthhelpers from@stellar/stellar-sdk; JWT signing key separate from Soroban signer.Definition of "Done": Common DoD;
docs/solver-onboarding.mdupdated.Resources:
Common Definition of "Done" (applies in addition to the criteria above):
npm run lint,npm run typecheck,npm test,npm run test:e2epass in CI..github/PULL_REQUEST_TEMPLATE, uses a Conventional Commit title (enforced by commitlint), includes test output / metrics screenshots, and references the issue..env.examplevariants andsrc/config/env.validation.ts(thecheck:env-driftscript must pass).