flex-auth/workplans/FLEX-WP-0017-action-bound-authorization-contract.md
repo-manager 4c3c528644
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(registrar): assign State Hub identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e47-6aac-7ee1-914d-0584c75d3c81
2026-08-23 13:21:43 +02:00

2.8 KiB

id type title domain repo status owner topic_slug planning_priority planning_order created updated state_hub_workstream_id
FLEX-WP-0017 workplan Action-bound authorization and durable approval contract infotech flex-auth active codex netkingdom P1 117 2026-08-23 2026-08-23 d75b7256-8b3d-5797-911c-96c3199b8baa

FLEX-WP-0017 - Action-bound authorization and durable approval contract

secrets-engine needs production authorization that binds an approval to an exact action, catalog lane, stage, targets, actor, purpose, validity window, and distinct approvers. The existing flex-auth decision response and State Hub decision object each provide only part of that contract.

Bind execute-time decisions to the evaluated request

id: FLEX-WP-0017-T01
status: done
priority: high
state_hub_task_id: "e7b47e1d-58e8-503c-be89-e8f2050215b1"

Add a structured binding to standalone DecisionEnvelope responses with the normalized subject, action, resource, context, and full SHA-256 request digest. Add schema and regression coverage. Prose remains diagnostic only.

Define the durable authorization object and semantics

id: FLEX-WP-0017-T02
status: done
priority: high
state_hub_task_id: "df7984fb-c31f-5b26-bf42-193e4c3cbb9f"

Publish schemas/action_authorization.schema.json and docs/action-bound-authorization-contract.md, including exact target mapping, validity, distinct approvals, supersession, and fail-closed outage semantics.

Add durable storage and authenticated approval evidence

id: FLEX-WP-0017-T03
status: wait
priority: high
state_hub_task_id: "82d39961-8140-5a7f-9bd8-5164dd1742e5"

State Hub must add a structured endpoint/object equivalent to the published contract, authenticated approval entries, and atomic supersession. Its current /decisions/{uuid} shape has only prose plus a single free-form decided_by. No flex-auth-local substitute is acceptable because flex-auth does not own the organizational approval lifecycle.

Propagate bindings through delegated evaluators

id: FLEX-WP-0017-T04
status: done
priority: medium
state_hub_task_id: "d85089ee-ad8c-502b-ba1b-be4ad23aec46"

Populate the same binding in Topaz, relationship, rule, and Keycloak adapter success and fail-closed responses using the shared canonical constructor.

Consumer handoff and live destructive-action proof

id: FLEX-WP-0017-T05
status: wait
priority: high
state_hub_task_id: "8c3fc0a2-0855-5ac9-afa5-d03b8b1f0bf9"

After T03, secrets-engine validates the canonical object before every privileged production action and proves wrong action/lane/stage/targets, expiry, supersession, outage, insufficient approvals, and duplicate approvers all fail before any OpenBao call. Live destroy stays disabled until that proof.