docs: track User Engine authority lookup implementation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
2a0586b4c9
commit
709848a9b1
2 changed files with 28 additions and 2 deletions
|
|
@ -20,8 +20,18 @@ composition; **no admitted HTTP adapter or production authority source**.
|
|||
An admitted authenticating gateway could supply that boundary, but no such
|
||||
composition is established by these sources.
|
||||
|
||||
These are source findings, not probes of deployed configurations. No owner
|
||||
repository, database, grant or credential was modified.
|
||||
These are source findings, not probes of deployed configurations. The follow-up
|
||||
User Engine commit `686da7c` adds `UserEngineService.lookup_account_authority`:
|
||||
an authorized exact issuer/subject/tenant lookup that never provisions a missing
|
||||
identity, returns current global and scoped account status (missing scoped state
|
||||
is explicit), and separates caller from target. The new policy action is
|
||||
`account.authority.read`; existing generic read grants are not assumed sufficient.
|
||||
Its result includes source observation time, identity/account references and the
|
||||
policy decision reference, but no root entitlement or profile data.
|
||||
|
||||
This closes the read-only **service primitive**, not the wire contract or admitted
|
||||
Hub workload. USER-WP-0037 owns root-grant/mapping disposition and authenticated
|
||||
HTTP exposure/private acceptance. No database, live grant or credential changed.
|
||||
|
||||
## Contract for owner disposition
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue