feat(tauth): rework TAuth

This commit is contained in:
Alois 2026-09-14 19:31:37 +02:00
commit 3685babebf
Signed by: alois
SSH key fingerprint: SHA256:GBzT2DXvAuGV9XIV5W3WrzVpjU54FThmxHXdbz95J24
31 changed files with 3418 additions and 502 deletions

5
todo.md Normal file
View file

@ -0,0 +1,5 @@
# Direct Iota TAuth
Add `DirectIota` connection mode to binary `.ta` format and Rust SDK.
Direct sessions must implement same TAuth MTP messages, signed authorization checks, exact redirect and PKCE binding, discovery revalidation, scope enforcement, one-time codes, metadata limits, and atomic revocation used by Omikron-routed sessions. Direct raw MTP access must not bypass grant checks.