docs: reconcile Claude readiness with authorization chain proof
All checks were successful
ci / validate (push) Successful in 1m32s
All checks were successful
ci / validate (push) Successful in 1m32s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
27a72537b2
commit
c67a22dbe2
3 changed files with 42 additions and 2 deletions
|
|
@ -258,3 +258,24 @@ record an unresolved approval/native action-vocabulary and embedded-claim
|
|||
digest mismatch for dual-control requests. This is owner integration evidence,
|
||||
not successful live activation; SECRETS-WP-0009-T03 remains wait. No new
|
||||
activation receipt was found in the Glas inbox. T02 remains waiting.
|
||||
|
||||
## 2026-09-06 authorization-chain owner return
|
||||
|
||||
Reviewed secrets-engine `f62d3fe` / `64aeec9`. Owner reports claim → Check →
|
||||
consume → backend integration against a throwaway OpenBao, including denial,
|
||||
unreachable service, invalid claim, missing digest, consume conflict and action
|
||||
mismatch refusal before backend access. Authorization transport is stubbed;
|
||||
wire shapes use published flex-auth fixtures. Do not describe this as a live
|
||||
production service or Anthropic delivery proof.
|
||||
|
||||
Owner now identifies deployment/configuration as the remaining live gate:
|
||||
consumer PDP service and approval-engine rollout, production service
|
||||
credentials, deployed policy pin and per-lane authorization id.
|
||||
SECRETS-WP-0009-T03 remains wait. Earlier digest-defect notes are historical;
|
||||
use this latest owner return for the integration status. Native lane positive/
|
||||
negative access checks, pinned Claude startup, provider scope/budget inputs and
|
||||
combined Glas acceptance remain outstanding. T02–T05 stay wait.
|
||||
|
||||
Review found no pending local changes or new inbox messages. Corrected stale
|
||||
README wording that still called owner execution missing; the implemented
|
||||
mechanism and its separate proofs do not change profile readiness.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue