flex-auth reported that its response channel is unauthenticated: pins serve plain HTTP and the envelope carries no signature, so a responder knowing the published package id and version can return a well-formed allow that passes every check a consumer makes. Their framing is the useful one -- fail-closed protects against a PDP that is absent, not against one that lies. That lands directly on this engine's correspondence chain. Matching pdp_digest proves two artifacts describe one request; it proves nothing about whether the decision is genuine, and an approval whose pdp_digest matches a forged decision matches perfectly. Every input to the comparison is either sent by the caller or published by the PDP. Our doc already said what pdp_digest cannot cover but did not say this, which is the limit most easily mistaken for coverage -- the digest chain looks like it closes authenticity and does not. Stated plainly, with the fix named as the PDP's to make (FLEX-WP-0024, signing the envelope) rather than something a consumer can recover. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D Assistant: claude-code Assistant-Model: opus Assistant-Process: 715850@bnt-lap001 Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e |
||
|---|---|---|
| .. | ||
| reviews | ||
| approval-claim.md | ||
| approval-consumption.md | ||
| caller-authentication.md | ||
| emission-cadence.md | ||
| flex-auth-handoff.md | ||
| gate-house-decision-request-claim-envelope.md | ||
| image-scan-2026-09-06.md | ||
| keycape-service-registrations.md | ||
| outbox-contract.md | ||
| pep-integration.md | ||
| storage-operations.md | ||