DQE Seal

Department of Questionable Engineering

DQE • doqe.org
HomeInventions › OAuth Refrigerator

OAuth Refrigerator

Identity-aware cold storage. OAuth 2.0 required before door release. Tokens expire every 60 minutes.

Patent Pending — DQE-RF-2025-002
← All Inventions

The OAuth Refrigerator is the Department's flagship identity-aware appliance. Cold storage access is gated behind a full OAuth 2.0 Authorization Code Flow with PKCE, ensuring that only authenticated, authorized personnel may retrieve chilled goods. The refrigerator supports Google, GitHub, and Apple sign-in. Microsoft Entra integration is listed on the roadmap under "future consideration."

When a user approaches the refrigerator, a 7-inch touch display activates and prompts sign-in. Upon successful authentication, an access token is issued. The door remains unlocked for the duration of token validity (default: 60 minutes). Upon token expiry, the door re-locks. Refresh tokens allow silent re-authentication for up to 24 hours, after which the user must complete the full flow again to access their leftovers.

Authentication Flow

  • Step 1 — Authorization Request: User taps the display. Refrigerator generates a PKCE code verifier and challenge, constructs the authorization URL, and displays a QR code. User scans with phone.
  • Step 2 — Identity Provider: User authenticates with chosen IdP (Google, GitHub, or Apple). Scopes requested: openid profile email refrigerator:open. Custom scope refrigerator:open must be pre-approved by DQE IAM team.
  • Step 3 — Callback: Authorization code returned to refrigerator's local callback server (http://fridge.local:8080/callback). Code exchanged for access and refresh tokens.
  • Step 4 — Door Release: Valid access token confirmed. Door solenoid disengages. User may now open refrigerator. Token stored in secure enclave in the door panel.
  • Step 5 — Re-lock: Door re-locks on close. Access token persists until expiry. Subsequent opens within the token window proceed without re-authentication.

Access Tiers

  • Standard Access: Full refrigerator access. Requires refrigerator:open scope.
  • Freezer Access: Separate scope: refrigerator:freezer. Must be requested independently. Approval: 2–3 business days.
  • Crisper Drawer: Governed by refrigerator:produce scope. Requires completion of DQE Vegetable Storage Awareness Training (Form DQE-RF-VEG) prior to scope grant.
  • Service Account Access: For meal-prep automation. Uses Client Credentials flow. Credentials stored in Vault. Rotation required every 90 days.

Emergency Access

In the event of IdP outage, network failure, or token infrastructure unavailability, users may request emergency physical access via Form DQE-RF-911 (Temporary Appliance Access Request). Processing time: 3–5 business days. Expedited processing (24 hours) available for perishable goods at imminent risk; requires documented evidence of spoilage urgency.

A physical override keyhole exists behind a DQE-sealed panel on the left side of the unit. The key is held by the Office of Appliance Oversight. Contact information is available during business hours (9 AM – 4 PM, excluding DQE administrative holidays).

Technical Specifications

  • Display: 7-inch capacitive touchscreen, 1024×600
  • Auth protocol: OAuth 2.0 + PKCE (RFC 7636)
  • Supported IdPs: Google, GitHub, Apple (Microsoft Entra: roadmap Q3 2026)
  • Token storage: Hardware secure enclave (door panel)
  • Network: WiFi 6 required; Ethernet adapter available (Form DQE-RF-NET)
  • Temperature: 2–4°C (refrigerator), -18°C (freezer); monitored via cloud dashboard
  • Power: Standard 120V / 240V; UPS recommended to prevent token loss during outages