Draft the gate-house decision request on the claim envelope
secrets-engine's PEP validator expects a flex-auth ActionAuthorization
but calls the governed claim endpoint. Research shows this is a
confirmation rather than a redesign: GH-DEC-2026-003 already names
GET /v1/approvals/{id}/claim as step 1 by endpoint and by field
(valid_now, which ActionAuthorization does not have), and
ActionAuthorization appears zero times in gate-house and state-hub. It
originates in flex-auth's own doc, which calls it a *proposed* shape for
the durable approval object that the same doc assigns to approval-engine.
Its required authority == state-hub also contradicts flex-auth's prose
that State Hub is not the runtime approval authority.
Request asks gate-house to confirm the claim is the step-1 artifact and
that ActionAuthorization is not required there, with PEPs validating
across the claim and the step-2 DecisionEnvelope they already fetch. No
safety property is lost; each check returns to the layer owning the data.
Records a ratified post-decision ActionAuthorization as a deferred option
with explicit revisit triggers, plus the constraint that such an object
cannot be served from the step-1 call, so it is not rediscovered later.
Also records why serving it at the claim endpoint and additively
extending the claim were rejected.
Files APPROVAL-IN-0002 to track the request. Docs only; 84 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 411227@bnt-lap001
Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535
This commit is contained in:
parent
2f4b7697fa
commit
7fd841f773
2 changed files with 169 additions and 0 deletions
|
|
@ -25,3 +25,34 @@ description: >-
|
|||
assigned; preserve mechanical replay and freshness semantics during adoption.
|
||||
state_hub_intake_id: "01a05ef0-a034-7ef8-bae1-45840392f40e"
|
||||
```
|
||||
|
||||
## APPROVAL-IN-0002 — Confirm the claim envelope on the PEP consumption path
|
||||
|
||||
```yaml
|
||||
id: APPROVAL-IN-0002
|
||||
kind: intake
|
||||
title: Confirm the claim envelope on the PEP consumption path
|
||||
status: open
|
||||
origin: coordination
|
||||
origin_ref: APPROVAL-WP-0002-T05
|
||||
priority: high
|
||||
owner: gate-house
|
||||
repo: approval-engine
|
||||
lane: blue
|
||||
tags:
|
||||
- decision-request
|
||||
- cross-repo
|
||||
created: '2026-09-06'
|
||||
updated: '2026-09-06'
|
||||
description: >-
|
||||
secrets-engine's PEP validator expects a flex-auth ActionAuthorization but
|
||||
calls GET /v1/approvals/{id}/claim, which serves approval-engine's governed
|
||||
approval-claim. GH-DEC-2026-003 already names the claim as the step-1
|
||||
artifact, and ActionAuthorization is an unratified flex-auth proposal absent
|
||||
from gate-house and state-hub. Requests gate-house confirm the claim is the
|
||||
step-1 artifact and that ActionAuthorization is not required on that path;
|
||||
a ratified post-decision ActionAuthorization is recorded as a deferred
|
||||
option with revisit triggers. Full request in
|
||||
docs/gate-house-decision-request-claim-envelope.md. Does not gate
|
||||
APPROVAL-WP-0002-T03.
|
||||
```
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue