chore(workplan): use canonical id for auth corrections
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e47-6aac-7ee1-914d-0584c75d3c81
This commit is contained in:
parent
c473f1971d
commit
350ffcea41
1 changed files with 5 additions and 3 deletions
|
|
@ -1,37 +0,0 @@
|
|||
---
|
||||
id: ADHOC-2026-08-23
|
||||
type: workplan
|
||||
title: "Inbound caller-auth and deployment documentation corrections"
|
||||
domain: infotech
|
||||
repo: flex-auth
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: netkingdom
|
||||
created: "2026-08-23"
|
||||
updated: "2026-08-23"
|
||||
---
|
||||
|
||||
## Classify rejected TokenReview credentials as unauthenticated
|
||||
|
||||
```task
|
||||
id: ADHOC-2026-08-23-T01
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Treat a successful TokenReview response that rejects a bearer token as an
|
||||
authentication failure (HTTP 401), while retaining HTTP 503 for transport,
|
||||
HTTP, and response-decode failures. Regression coverage exercises the reviewer
|
||||
and authenticator seam.
|
||||
|
||||
## Correct NetworkPolicy egress documentation
|
||||
|
||||
```task
|
||||
id: ADHOC-2026-08-23-T02
|
||||
status: done
|
||||
priority: low
|
||||
```
|
||||
|
||||
Document that caller-authenticated pins permit TCP 443 and 6443 without a
|
||||
destination selector for Kubernetes TokenReview, while pins without caller
|
||||
authentication retain deny-all egress.
|
||||
Loading…
Add table
Add a link
Reference in a new issue