docs: track User Engine authority lookup implementation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
2a0586b4c9
commit
709848a9b1
2 changed files with 28 additions and 2 deletions
|
|
@ -497,6 +497,22 @@ Validation: **433 ordinary tests** and **six disposable PostgreSQL tests** pass;
|
|||
full `make ci-check` inventory/build/isolated-wheel checks pass. The facts module
|
||||
is included in the distribution.
|
||||
|
||||
## User Engine lookup implementation — 2026-09-28
|
||||
|
||||
Implemented and committed User Engine `686da7c`: an independently authorized
|
||||
`lookup_account_authority` service operation for exact issuer/subject/tenant.
|
||||
It never provisions unknown identities, returns current global/scoped state,
|
||||
keeps caller separate from lookup target, and exposes no root grant or profile
|
||||
PII. Unknown, disabled, missing-scoped-account and denied lookups have tests.
|
||||
User Engine `make test` ran **270 tests** successfully with eight optional skips;
|
||||
layer conformance passed. The six new checks use local fixtures.
|
||||
|
||||
USER-WP-0037-T01 is done. Its T02 tracks root-entitlement/mapping disposition;
|
||||
T03 tracks authenticated workload HTTP exposure and private acceptance. Hub's
|
||||
[owner contract](../docs/owner-facts-contract.md) records this service primitive
|
||||
without treating it as a connected HTTP adapter. T01/T02 here remain `progress`.
|
||||
No Tenant Engine source, live credential/grant or deployment was changed.
|
||||
|
||||
## Acceptance checkpoints
|
||||
|
||||
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue