docs: track User Engine authority lookup implementation
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 18:19:24 +02:00
parent 2a0586b4c9
commit 709848a9b1
2 changed files with 28 additions and 2 deletions

View file

@ -20,8 +20,18 @@ composition; **no admitted HTTP adapter or production authority source**.
An admitted authenticating gateway could supply that boundary, but no such
composition is established by these sources.
These are source findings, not probes of deployed configurations. No owner
repository, database, grant or credential was modified.
These are source findings, not probes of deployed configurations. The follow-up
User Engine commit `686da7c` adds `UserEngineService.lookup_account_authority`:
an authorized exact issuer/subject/tenant lookup that never provisions a missing
identity, returns current global and scoped account status (missing scoped state
is explicit), and separates caller from target. The new policy action is
`account.authority.read`; existing generic read grants are not assumed sufficient.
Its result includes source observation time, identity/account references and the
policy decision reference, but no root entitlement or profile data.
This closes the read-only **service primitive**, not the wire contract or admitted
Hub workload. USER-WP-0037 owns root-grant/mapping disposition and authenticated
HTTP exposure/private acceptance. No database, live grant or credential changed.
## Contract for owner disposition

View file

@ -497,6 +497,22 @@ Validation: **433 ordinary tests** and **six disposable PostgreSQL tests** pass;
full `make ci-check` inventory/build/isolated-wheel checks pass. The facts module
is included in the distribution.
## User Engine lookup implementation — 2026-09-28
Implemented and committed User Engine `686da7c`: an independently authorized
`lookup_account_authority` service operation for exact issuer/subject/tenant.
It never provisions unknown identities, returns current global/scoped state,
keeps caller separate from lookup target, and exposes no root grant or profile
PII. Unknown, disabled, missing-scoped-account and denied lookups have tests.
User Engine `make test` ran **270 tests** successfully with eight optional skips;
layer conformance passed. The six new checks use local fixtures.
USER-WP-0037-T01 is done. Its T02 tracks root-entitlement/mapping disposition;
T03 tracks authenticated workload HTTP exposure and private acceptance. Hub's
[owner contract](../docs/owner-facts-contract.md) records this service primitive
without treating it as a connected HTTP adapter. T01/T02 here remain `progress`.
No Tenant Engine source, live credential/grant or deployment was changed.
## Acceptance checkpoints
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core