Skip to content

Mike Sync v2 review: PR #317 - #124

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
agent/upstream-sync-high-20260819145640
Draft

Mike Sync v2 review: PR #317#124
github-actions[bot] wants to merge 1 commit into
mainfrom
agent/upstream-sync-high-20260819145640

Conversation

@github-actions

Copy link
Copy Markdown

Automated-Upstream-Mike-Sync: true
Upstream-Risk: high

Promising settings consolidation, but MFA, Supabase configuration, provider-key, privacy, and routing changes cross protected boundaries and require review.

Mike PR Open-Legal-Products#317

  • Outcome: needs-decision
  • Capability: ROSS-native unified settings area with reproducible local MFA support
  • Series: settings-security
  • Dependencies: Mike PR feat: implement multi-factor authentication (MFA) setup and verification flow and data deletion and export Open-Legal-Products/mike#172 MFA enrollment and verification capability, Supabase Auth MFA and local CLI stack, Existing ROSS account settings, API-key, connector, privacy, and MFA enforcement seams
  • Prerequisites: Security review comparing local Supabase MFA behavior with deployed authentication, Product decision on canonical /account versus /settings routes and redirects, Focused MFA enrollment, login-gate, step-up, unenrollment, and redirect test evidence, Review of Supabase configuration, schema, provider-key, privacy, and prompt changes
  • Reason: ROSS already has the underlying account settings and MFA flows, but PR Refactor settings and enable local MFA Open-Legal-Products/mike#317 couples their route/UI consolidation to authentication and Supabase configuration; equivalence and safe migration cannot be established without security and product decisions.

Architecture brief

Retain ROSS MFA enforcement and data APIs; independently migrate the existing account pages to a settings shell with compatibility redirects, while treating local Supabase MFA configuration as a separately reviewed authentication-boundary change.

Implementation plan

  • Define route ownership and backward-compatible redirects for every existing /account path.
  • Create a local Supabase MFA harness covering enrollment, AAL2 login enforcement, step-up operations, unenrollment, and redirect allow-lists.
  • Diff the proposed local configuration against deployed Supabase authentication policy and approve only intentional parity differences.
  • Migrate the presentation layer onto current ROSS settings seams without replacing MFA middleware, profile persistence, provider-key handling, or privacy controls.
  • Run focused frontend, backend, and end-to-end regression tests before adoption.

Required human action

This is a draft state-only architecture record. Review the brief and implementation plan before any code is attempted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants