secrets-engine found that flex-auth hashes context into the request digest while the dual-control pattern carries the claim in context.approval, so a pdp_digest recorded at issue cannot equal the digest of the request that carries the claim. The resolution is forced by ordering rather than chosen: issue precedes the decision, so pdp_digest is necessarily the digest of the underlying action request before any claim is embedded in it. A claim cannot carry the digest of a document containing that claim -- the value would have to be known before it could be computed. Record that, and record the limit of our authority: the exact exclusion rule belongs to the PDP's digest contract, not here. This engine stores what it was given at issue and does not compute it. Warn consumers not to guess the exclusion, because comparing digests derived under different rules fails open toward accepting a claim bound to a different request. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvyJPAaVCGsVheVhcCwNND Assistant: claude-code Assistant-Model: opus Assistant-Process: 411227@bnt-lap001 Assistant-Session: d566f6d3-bcaf-43c3-bc5e-3ddd0f64b535 |
||
|---|---|---|
| .. | ||
| approval-claim.md | ||
| approval-consumption.md | ||
| caller-authentication.md | ||
| emission-cadence.md | ||
| flex-auth-handoff.md | ||
| gate-house-decision-request-claim-envelope.md | ||
| keycape-service-registrations.md | ||
| outbox-contract.md | ||
| pep-integration.md | ||
| storage-operations.md | ||