approval-engine/workplans
tegwick 24ec18fe3f Refuse to invent the human approver client_id and callback URI
key-cape (KEY-WP-0013-T02) asked for two exact strings for the human
approver registration. This engine is a bearer-token resource server: no
redirect endpoint, no authorization-code/PKCE path, and no Ingress or
external origin, so neither string exists here. Record why, name the
missing owner (a browser-facing approver UI outside this repo), and
confirm that the access token — never the ID token — is what this
resource validates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HyybaE7DUXrWYrhbnESCTe

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275879@bnt-lap001
Assistant-Session: eb464208-f821-41b2-bc5a-a6c33d92a8ad
2026-09-08 14:47:40 +02:00
..
APPROVAL-WP-0001-v07-alignment-and-engine-spine.md Finish approval engine spine 2026-09-01 23:45:48 +02:00
APPROVAL-WP-0002-production-readiness-and-consumer-adoption.md Refuse to invent the human approver client_id and callback URI 2026-09-08 14:47:40 +02:00