Files
praxis/server
Praxis CI 46b46479ca feat(P01): SLICE-06 P1 integration — wire lifespan + auth + verification swap
- TASK-06-01 __main__.py: SessionMiddleware (signed cookies, D-056) added
  AFTER CORS so it is outermost. slowapi limiter state + 429 exception
  handler registered. The lifespan (TASK-01-03) now also runs the VC key
  migration on first boot.
- TASK-06-02 __main__.py: auth_router mounted (POST /api/operator/login,
  POST /api/operator/logout, GET /api/operator/me) BEFORE the StaticFiles
  mount (routes-before-static constraint). Auth routes use app.state.pg_store
  (503 if no Postgres).
- TASK-06-03 __main__.py: /vc/verify swapped to the two-store path (G-011):
  pg_store for key lookup (active + superseded), SQLite fallback for v0.3
  credentials, SQLite-only if no Postgres. _maybe_migrate_issuer_keys()
  runs once in the lifespan (idempotent, G-027 first-boot, non-fatal on
  failure — v0.3 path intact).
- TASK-06-04 tests/test_p1_auth_integration.py: 4 e2e tests (skip if no
  Postgres) — full auth flow, /me without cookie 401, wrong password 401,
  learner voice loop unaffected (REQ-NFR-MT-01).
- TASK-06-05 tests/test_p1_vc_migration_e2e.py: 5 e2e tests (skip if no
  Postgres) — R-VC-MIG-01 critical (v0.3 VC verifies against archived
  superseded key in Postgres), idempotent migration, G-027 first-boot,
  v0.04 VC verifies, tamper detection.

Graceful degradation verified: server starts without Postgres (pg_pool/
pg_store are None; voice loop works; auth routes return 503).

---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: backend-engineer
task: 06-01,06-02,06-03,06-04,06-05
requirements:
  covered: [REQ-MT-01, REQ-AUTH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01]
  grill:
    - G-011 (two-store fallback wired in /vc/verify)
  risks:
    - R-VC-MIG-01 (e2e test: v0.3 VC verifies against archived superseded key in Postgres)
---/ci---
2026-08-04 01:00:11 +00:00
..