docs: track User Engine authority lookup implementation
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 18:19:24 +02:00
parent 2a0586b4c9
commit 709848a9b1
2 changed files with 28 additions and 2 deletions

View file

@ -20,8 +20,18 @@ composition; **no admitted HTTP adapter or production authority source**.
An admitted authenticating gateway could supply that boundary, but no such
composition is established by these sources.
These are source findings, not probes of deployed configurations. No owner
repository, database, grant or credential was modified.
These are source findings, not probes of deployed configurations. The follow-up
User Engine commit `686da7c` adds `UserEngineService.lookup_account_authority`:
an authorized exact issuer/subject/tenant lookup that never provisions a missing
identity, returns current global and scoped account status (missing scoped state
is explicit), and separates caller from target. The new policy action is
`account.authority.read`; existing generic read grants are not assumed sufficient.
Its result includes source observation time, identity/account references and the
policy decision reference, but no root entitlement or profile data.
This closes the read-only **service primitive**, not the wire contract or admitted
Hub workload. USER-WP-0037 owns root-grant/mapping disposition and authenticated
HTTP exposure/private acceptance. No database, live grant or credential changed.
## Contract for owner disposition