Require fresh KeyCape authentication for decision review sign-in
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
parent
c70d63abf9
commit
3f1c9ecd8a
6 changed files with 23 additions and 1 deletions
12
docs/evidence/2026-09-16-review-fresh-authentication.json
Normal file
12
docs/evidence/2026-09-16-review-fresh-authentication.json
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
{
|
||||
"task": "SECRETS-WP-0010-T03",
|
||||
"observation_id": "9e56e4a1-70e4-4055-9510-6734fb6357b2",
|
||||
"observed_at": "2026-09-15T23:32:13.223283+00:00",
|
||||
"authentication_at": "2026-09-15T23:15:12+00:00",
|
||||
"authentication_age_seconds": 1021.223283,
|
||||
"policy_maximum_age_seconds": 900,
|
||||
"finding": "The exact memo, version, approval binding, human identity, group, tenant provenance and MFA shape match; freshness exceeds policy allowance. Review login omitted prompt/max_age and allowed older KeyCape SSO authentication to be reused.",
|
||||
"change": "Request prompt=login and max_age=0 from KeyCape; preserve signed assurance timestamps and policy freshness requirement.",
|
||||
"validation": "119 browser and review tests passed with local Approval Engine component; existing KeyCape TestFreshLoginRequirementsReachProvider covers forwarding these parameters. Live human reauthentication remains to be performed by the operator.",
|
||||
"image": "forgejo.coulomb.social/coulomb/informed-decision@sha256:d08bdced387a3f24bac0c735d91ad4e2d0ed50cd96e58431343a60eee6421d82"
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue