Confirm the approval-claim as the step-1 PEP artifact
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator expects a flex-auth ActionAuthorization but fetches the approval-claim endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path. GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is the step-1 artifact and always was — ActionAuthorization is unratified, has no valid_now field, and cannot be served from a step-1 call. The addition beyond confirmation is doctrine: a PEP validates each artifact against the layer that owns its data, and no PIP republishes the PDP's decision. The provenance.authority == "state-hub" requirement is struck; State Hub is a read model and holds no runtime approval authority. docs/contracts/approval-consumption.md carries the amendment at the sequence itself so implementers find it there. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
parent
60e2e7de65
commit
1a920a5490
3 changed files with 115 additions and 3 deletions
|
|
@ -131,7 +131,7 @@ state_hub_intake_id: "01a04b04-dd82-73a4-a8bf-9aeba5ef575f"
|
|||
id: GH-IN-0002
|
||||
kind: intake
|
||||
title: Claim envelope on the PEP consumption path — which artifact is step 1 of GH-DEC-2026-003
|
||||
status: open
|
||||
status: closed
|
||||
origin: cross-repo
|
||||
origin_ref: approval-engine APPROVAL-IN-0002 (decision request)
|
||||
priority: high
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue