Name the execute-time digest target; record the tenant collision
flex-auth published binding.approval_binding_digest (FLEX-DEC-2026-007) after
secrets-engine found that a claim-bearing request's request_digest covers the
carried claim, so it can never equal a pdp_digest recorded before that claim
existed. A consumer obeying GH-DEC-2026-008 against request_digest would have
failed closed permanently on every claim rather than on a bad one.
The value recorded at issue was already correct, so no code changes. What was
wrong was this repo's description of the comparison target: a reader would
reach for request_digest and fail closed forever. The schema and
docs/approval-claim.md now name approval_binding_digest as the execute-time
target and state that request_digest is never it, while leaving the issue-time
description as it stood.
Separately, docs/keycape-service-registrations.md now records a live collision
in the deployment inputs: the manifest serves --tenant platform while the
requested registrations issue tenant:coulomb, and ApiApplication.identity
compares them with exact string equality before any object lookup, so those
tokens would be denied 403 on every non-health route. flex-auth's
tenant:platform is a PDP subject this engine never reads and cannot bridge the
two. The values are left as-is on purpose — resolving it needs an owner
statement on whether the two name the same layer, and guessing grants
cross-tenant access to the approval store. The doc's stale issuer is corrected
to the live https://kc.coulomb.social from 06544b0.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
This commit is contained in:
parent
06544b0fb4
commit
5c87ba8610
4 changed files with 115 additions and 12 deletions
|
|
@ -75,6 +75,21 @@ delivery. Requested KeyCape registrations are in
|
|||
`approval-engine`, not the OAuth client id). Remains `progress` until KeyCape
|
||||
owns and proves those audience/client/scope registrations.
|
||||
|
||||
2026-09-06 follow-up: a tenant collision in the deployment inputs is now
|
||||
recorded in `docs/keycape-service-registrations.md`. The manifest serves
|
||||
`--tenant platform` while the requested client registrations issue
|
||||
`tenant: tenant:coulomb`, and `ApiApplication.identity` compares the two with
|
||||
exact string equality before any object lookup — so tokens issued under the
|
||||
current registrations would be denied `403` on every non-health route.
|
||||
flex-auth's `tenant:platform` CheckRequest subject is a PDP input this engine
|
||||
never reads and cannot participate in the comparison. Denial evidence:
|
||||
`tests/test_auth.py::test_wrong_tenant_is_forbidden`. The values are left as-is
|
||||
deliberately: resolving it requires an owner statement on whether `platform` and
|
||||
`tenant:coulomb` name the same layer, and guessing grants cross-tenant access to
|
||||
the approval store. The registrations doc's stale issuer
|
||||
(`https://auth.netkingdom.local`) is corrected to the live
|
||||
`https://kc.coulomb.social` from `06544b0`. T01 stays `progress`.
|
||||
|
||||
## Harden durable storage and migrations
|
||||
|
||||
```task
|
||||
|
|
@ -249,6 +264,19 @@ never inferred from an incidental digest, and never back-filled: legacy rows
|
|||
migrate to `false` and a successor inherits its predecessor's declaration.
|
||||
Schema, both examples, and a v2→v3 migration test cover it (102 tests).
|
||||
|
||||
2026-09-06 follow-up (envelope target): flex-auth published
|
||||
`binding.approval_binding_digest` (`FLEX-DEC-2026-007`) — the request digest
|
||||
material with `context.approval` removed — because a claim-bearing request's
|
||||
`request_digest` covers the carried claim and can therefore never equal a
|
||||
`pdp_digest` recorded at issue. A consumer obeying `GH-DEC-2026-008` against
|
||||
`request_digest` would have failed closed permanently on every claim, which is
|
||||
the defect secrets-engine and flex-auth both hit. The value this engine records
|
||||
at issue is unchanged and correct; only the consumer-side comparison target
|
||||
needed naming. `schemas/approval_claim.schema.json` and `docs/approval-claim.md`
|
||||
now name `approval_binding_digest` as the execute-time target and state that
|
||||
`request_digest` is never it. No code change was required, so T05 stays `wait`
|
||||
on the deployed base URL (T03).
|
||||
|
||||
## Production preflight — 2026-09-06 Glas deployment session
|
||||
|
||||
User authorized production deployment. Live cluster inspection confirms no
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue