feat: add OIDC browser sessions with live access enforcement
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:17:16 +02:00
parent fdea2f5192
commit a15fe032b0
14 changed files with 807 additions and 31 deletions

View file

@ -1,7 +1,7 @@
# Platform-root access inventory — 2026-09-28
This is the coverage baseline for HUB-WP-0012-T01, not an access grant or a
passing security test. It enumerates 161 Hub source surfaces (88 runtime route
passing security test. It enumerates 165 Hub source surfaces (92 runtime route
registrations, 42 embedded router operations, 31 MCP tools), 39 observed cluster
namespaces and nine additional extension/native-management boundaries. All 250
observed Deployment/StatefulSet/DaemonSet/CronJob/Service/Ingress objects map to
@ -19,7 +19,9 @@ pending owner confirmation; none establishes an effective platform-root grant.
Hub source revision is recorded in the JSON. Runtime routes are constructed
locally without running startup, sending requests or connecting to a database.
The optional inbox router is included separately. Compatibility aliases and
The optional inbox and browser-session routers are included separately. Browser
login initiation and callback are exact protocol entry points; they do not
grant access without verified tokens and live root authorization. Compatibility aliases and
FastAPI built-in documentation endpoints are included even when absent from
OpenAPI; disabled compatibility groups still belong in the coverage contract.
Embedded factories are scanned with their default prefixes and include optional