feat: add fail-closed Hub access profile foundation
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 11:44:50 +02:00
parent df39fd5f43
commit 3e386147fd
35 changed files with 2009 additions and 195 deletions

7
tests/fixtures/flex-auth/README.md vendored Normal file
View file

@ -0,0 +1,7 @@
These public conformance fixtures were copied from flex-auth
`examples/secrets-engine/replay/` and `check_request_allow_rotate.json` on
2026-09-28. They retain the owner's Go-generated signature and submitted digest.
`keys.json` contains a well-known **test-only public key**, not production trust.
The old decision is used only to test cryptographic interoperability, never as
an active authorization decision. Hub policy lifetime/caller tests use fresh
synthetic decisions with ephemeral test keys.