43 lines
2.4 KiB
Markdown
43 lines
2.4 KiB
Markdown
|
|
# HUB-WP-0012 source implementation evidence — 2026-09-28
|
|||
|
|
|
|||
|
|
This is local source evidence, not attended login, deployed policy, extension or
|
|||
|
|
Railiance acceptance. The workplan remains active with T01–T04 in progress.
|
|||
|
|
|
|||
|
|
Validation:
|
|||
|
|
|
|||
|
|
- `.venv/bin/python -m pytest -q --disable-warnings`: **271 passed** in 50.43s.
|
|||
|
|
One existing FastAPI/Starlette TestClient deprecation warning.
|
|||
|
|
- `tools/build_access_inventory.py --inventory docs/platform-access-inventory.json
|
|||
|
|
--check`: **161 Hub surfaces, 48 platform rows, 250 cluster objects**; checks pass.
|
|||
|
|
- `uv build`: source distribution and wheel build successfully; wheel contains
|
|||
|
|
`hub_core/security/routes.json`.
|
|||
|
|
- `git diff --check`: passes.
|
|||
|
|
|
|||
|
|
Tests cover catalog-wide anonymous denial, exact minimal health exception,
|
|||
|
|
production default denial without owner adapters, immutable root/assurance checks,
|
|||
|
|
live fact freshness and suspension/entitlement withdrawal, denied/unavailable
|
|||
|
|
policy, durable-audit failure, body replay and producer binding, event provenance,
|
|||
|
|
concurrent request contexts, an embedded host, MCP invocation credential isolation
|
|||
|
|
and error redaction, signed JWT claim validation and issuer-key rotation, signed
|
|||
|
|
PDP binding/lifetime/caller/obligation rejection, and projected caller-token rotation.
|
|||
|
|
|
|||
|
|
Interoperability uses flex-auth's original public test fixtures (signed, tampered,
|
|||
|
|
public verification key and original request). Both signature verification and
|
|||
|
|
`submitted_request_digest` reproduction pass against the Go-generated artifacts.
|
|||
|
|
Synthetic current decisions exercise the live-time checks; the historical fixture
|
|||
|
|
is never treated as an active authorization grant.
|
|||
|
|
|
|||
|
|
The [profile candidate](../access-profile-v1.md) states configuration, bounded
|
|||
|
|
lifetimes, serialization limits, extension/host responsibilities, and release gates.
|
|||
|
|
No live credential, grant, policy, workload, public listener or retirement state
|
|||
|
|
was changed. No private production signing key or root subject was invented.
|
|||
|
|
|
|||
|
|
State Hub implementation decision:
|
|||
|
|
`6edd5720-c894-46e3-8130-fd6c09b9f311`.
|
|||
|
|
|
|||
|
|
Remaining requirements include owner review and per-service route expansion;
|
|||
|
|
attended root binding/PKCE/MFA/logout; real account/tenant and durable audit adapters;
|
|||
|
|
a dedicated Hub PDP with authenticated caller and signing-key delivery; deployment
|
|||
|
|
composition and owner health checks; all client/extension/platform receipts;
|
|||
|
|
separately approved exposure; and Phase 2 tenant isolation/delegation.
|