Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e47-6aac-7ee1-914d-0584c75d3c81
2.4 KiB
| id | type | title | domain | repo | status | owner | topic_slug | planning_priority | planning_order | created | updated |
|---|---|---|---|---|---|---|---|---|---|---|---|
| FLEX-WP-0017 | workplan | Action-bound authorization and durable approval contract | infotech | flex-auth | active | codex | netkingdom | P1 | 117 | 2026-08-23 | 2026-08-23 |
FLEX-WP-0017 - Action-bound authorization and durable approval contract
secrets-engine needs production authorization that binds an approval to an exact action, catalog lane, stage, targets, actor, purpose, validity window, and distinct approvers. The existing flex-auth decision response and State Hub decision object each provide only part of that contract.
Bind execute-time decisions to the evaluated request
id: FLEX-WP-0017-T01
status: done
priority: high
Add a structured binding to standalone DecisionEnvelope responses with the
normalized subject, action, resource, context, and full SHA-256 request digest.
Add schema and regression coverage. Prose remains diagnostic only.
Define the durable authorization object and semantics
id: FLEX-WP-0017-T02
status: done
priority: high
Publish schemas/action_authorization.schema.json and
docs/action-bound-authorization-contract.md, including exact target mapping,
validity, distinct approvals, supersession, and fail-closed outage semantics.
Add durable storage and authenticated approval evidence
id: FLEX-WP-0017-T03
status: wait
priority: high
State Hub must add a structured endpoint/object equivalent to the published
contract, authenticated approval entries, and atomic supersession. Its current
/decisions/{uuid} shape has only prose plus a single free-form decided_by.
No flex-auth-local substitute is acceptable because flex-auth does not own the
organizational approval lifecycle.
Propagate bindings through delegated evaluators
id: FLEX-WP-0017-T04
status: done
priority: medium
Populate the same binding in Topaz, relationship, rule, and Keycloak adapter success and fail-closed responses using the shared canonical constructor.
Consumer handoff and live destructive-action proof
id: FLEX-WP-0017-T05
status: wait
priority: high
After T03, secrets-engine validates the canonical object before every privileged production action and proves wrong action/lane/stage/targets, expiry, supersession, outage, insufficient approvals, and duplicate approvers all fail before any OpenBao call. Live destroy stays disabled until that proof.