Identity-aware cold storage. OAuth 2.0 required before door release. Tokens expire every 60 minutes.
Patent Pending — DQE-RF-2025-002The OAuth Refrigerator is the Department's flagship identity-aware appliance. Cold storage access is gated behind a full OAuth 2.0 Authorization Code Flow with PKCE, ensuring that only authenticated, authorized personnel may retrieve chilled goods. The refrigerator supports Google, GitHub, and Apple sign-in. Microsoft Entra integration is listed on the roadmap under "future consideration."
When a user approaches the refrigerator, a 7-inch touch display activates and prompts sign-in. Upon successful authentication, an access token is issued. The door remains unlocked for the duration of token validity (default: 60 minutes). Upon token expiry, the door re-locks. Refresh tokens allow silent re-authentication for up to 24 hours, after which the user must complete the full flow again to access their leftovers.
openid profile email refrigerator:open. Custom scope refrigerator:open must be pre-approved by DQE IAM team.http://fridge.local:8080/callback). Code exchanged for access and refresh tokens.refrigerator:open scope.refrigerator:freezer. Must be requested independently. Approval: 2–3 business days.refrigerator:produce scope. Requires completion of DQE Vegetable Storage Awareness Training (Form DQE-RF-VEG) prior to scope grant.In the event of IdP outage, network failure, or token infrastructure unavailability, users may request emergency physical access via Form DQE-RF-911 (Temporary Appliance Access Request). Processing time: 3–5 business days. Expedited processing (24 hours) available for perishable goods at imminent risk; requires documented evidence of spoilage urgency.
A physical override keyhole exists behind a DQE-sealed panel on the left side of the unit. The key is held by the Office of Appliance Oversight. Contact information is available during business hours (9 AM – 4 PM, excluding DQE administrative holidays).