Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
42 lines
2.4 KiB
Markdown
42 lines
2.4 KiB
Markdown
# HUB-WP-0012 source implementation evidence — 2026-09-28
|
||
|
||
This is local source evidence, not attended login, deployed policy, extension or
|
||
Railiance acceptance. The workplan remains active with T01–T04 in progress.
|
||
|
||
Validation:
|
||
|
||
- `.venv/bin/python -m pytest -q --disable-warnings`: **271 passed** in 50.43s.
|
||
One existing FastAPI/Starlette TestClient deprecation warning.
|
||
- `tools/build_access_inventory.py --inventory docs/platform-access-inventory.json
|
||
--check`: **161 Hub surfaces, 48 platform rows, 250 cluster objects**; checks pass.
|
||
- `uv build`: source distribution and wheel build successfully; wheel contains
|
||
`hub_core/security/routes.json`.
|
||
- `git diff --check`: passes.
|
||
|
||
Tests cover catalog-wide anonymous denial, exact minimal health exception,
|
||
production default denial without owner adapters, immutable root/assurance checks,
|
||
live fact freshness and suspension/entitlement withdrawal, denied/unavailable
|
||
policy, durable-audit failure, body replay and producer binding, event provenance,
|
||
concurrent request contexts, an embedded host, MCP invocation credential isolation
|
||
and error redaction, signed JWT claim validation and issuer-key rotation, signed
|
||
PDP binding/lifetime/caller/obligation rejection, and projected caller-token rotation.
|
||
|
||
Interoperability uses flex-auth's original public test fixtures (signed, tampered,
|
||
public verification key and original request). Both signature verification and
|
||
`submitted_request_digest` reproduction pass against the Go-generated artifacts.
|
||
Synthetic current decisions exercise the live-time checks; the historical fixture
|
||
is never treated as an active authorization grant.
|
||
|
||
The [profile candidate](../access-profile-v1.md) states configuration, bounded
|
||
lifetimes, serialization limits, extension/host responsibilities, and release gates.
|
||
No live credential, grant, policy, workload, public listener or retirement state
|
||
was changed. No private production signing key or root subject was invented.
|
||
|
||
State Hub implementation decision:
|
||
`6edd5720-c894-46e3-8130-fd6c09b9f311`.
|
||
|
||
Remaining requirements include owner review and per-service route expansion;
|
||
attended root binding/PKCE/MFA/logout; real account/tenant and durable audit adapters;
|
||
a dedicated Hub PDP with authenticated caller and signing-key delivery; deployment
|
||
composition and owner health checks; all client/extension/platform receipts;
|
||
separately approved exposure; and Phase 2 tenant isolation/delegation.
|