From 5071759c43c225738ed533783380ff7feb8a9d25 Mon Sep 17 00:00:00 2001 From: custodian-sync Date: Sun, 6 Sep 2026 22:34:03 +0200 Subject: [PATCH] chore(consistency): sync task status from DB [auto] Updated by fix-consistency on 2026-09-06: - update .custodian-brief.md for flex-auth Assistant: claude-code Assistant-Model: opus Assistant-Process: 715613@bnt-lap001 Assistant-Session: fabd95c1-4c9e-4080-8849-8707ae025f80 --- .custodian-brief.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/.custodian-brief.md b/.custodian-brief.md index 858d3fe..d1669a5 100644 --- a/.custodian-brief.md +++ b/.custodian-brief.md @@ -2,12 +2,20 @@ # Custodian Brief — flex-auth **Domain:** infotech -**Last synced:** 2026-09-06 18:39 UTC +**Last synced:** 2026-09-06 20:34 UTC **State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)* ## Active Workstreams -*(none — repo may need first-session setup)* +### Operator caller access path and caller identity in the decision record +Progress: 0/5 done | workplan_id: `ad011f92-786c-51ad-b3f6-c06ad77e7af7` + +**Open tasks:** +- ! 2. Run the positive and negative tests and return the receipts `79a8d82d` +- ! 3. Flip `callerAuth.mode` to enforce `8117c9d8` +- ! 5. Report the gap to gate-house as a v0.8 finding `d685abfc` +- · 1. Create the ServiceAccount the deployed binding already names `10e5a40c` +- · 4. Record the authenticated caller in the decision record `c0e4f31a` --- ## MCP Orientation (when available)