hub-core/docs/evidence/hub-wp-0012-source-20260928.md
tegwick 3e386147fd
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s
feat: add fail-closed Hub access profile foundation
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
2026-09-28 11:44:50 +02:00

2.4 KiB
Raw Blame History

HUB-WP-0012 source implementation evidence — 2026-09-28

This is local source evidence, not attended login, deployed policy, extension or Railiance acceptance. The workplan remains active with T01–T04 in progress.

Validation:

  • .venv/bin/python -m pytest -q --disable-warnings: 271 passed in 50.43s. One existing FastAPI/Starlette TestClient deprecation warning.
  • tools/build_access_inventory.py --inventory docs/platform-access-inventory.json --check: 161 Hub surfaces, 48 platform rows, 250 cluster objects; checks pass.
  • uv build: source distribution and wheel build successfully; wheel contains hub_core/security/routes.json.
  • git diff --check: passes.

Tests cover catalog-wide anonymous denial, exact minimal health exception, production default denial without owner adapters, immutable root/assurance checks, live fact freshness and suspension/entitlement withdrawal, denied/unavailable policy, durable-audit failure, body replay and producer binding, event provenance, concurrent request contexts, an embedded host, MCP invocation credential isolation and error redaction, signed JWT claim validation and issuer-key rotation, signed PDP binding/lifetime/caller/obligation rejection, and projected caller-token rotation.

Interoperability uses flex-auth's original public test fixtures (signed, tampered, public verification key and original request). Both signature verification and submitted_request_digest reproduction pass against the Go-generated artifacts. Synthetic current decisions exercise the live-time checks; the historical fixture is never treated as an active authorization grant.

The profile candidate states configuration, bounded lifetimes, serialization limits, extension/host responsibilities, and release gates. No live credential, grant, policy, workload, public listener or retirement state was changed. No private production signing key or root subject was invented.

State Hub implementation decision: 6edd5720-c894-46e3-8130-fd6c09b9f311.

Remaining requirements include owner review and per-service route expansion; attended root binding/PKCE/MFA/logout; real account/tenant and durable audit adapters; a dedicated Hub PDP with authenticated caller and signing-key delivery; deployment composition and owner health checks; all client/extension/platform receipts; separately approved exposure; and Phase 2 tenant isolation/delegation.