Connect policy-gated browser review and audit runtime

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 00:31:03 +02:00
parent 2cc32168ac
commit 83849b75d4
35 changed files with 2381 additions and 83 deletions

View file

@ -8,7 +8,7 @@ status: active
owner: claude
topic_slug: netkingdom
created: "2026-09-09"
updated: "2026-09-09"
updated: "2026-09-11"
reviewed_at: "2026-09-09"
reviewed_against_commit: "ee2cca5"
reviewed_note: >-
@ -568,6 +568,50 @@ in reconciliation, supply native custody and registered human/deployed-engine
proof. These remain live work in this task; `/readyz` stays 503 and browser bind
routes remain absent. Details: `docs/durable-review-evidence.md`.
2026-09-11 — **protected review and actual browser exercise implemented.**
The configured `0.2.0` service now connects the named memo to fresh Flex Auth
checks before render, download, acknowledgment and each human response. The
separate workload caller, exact package/version/digest and submitted request
binding are validated; observations are immutable and retain
`decision_attributable=false`. No presentation claim becomes a policy input.
Actual native component checks cover caller enforcement, request digest wire
format and registry enrichment, with fixture-only assignments and credentials.
The browser supports explicit highlights, accept/return/discuss/decline, current
actor/version/session/act checks, original confirmed correlation and visible
uncertain submissions without POST retry. An audit thread drains bounded batches,
emits declared heartbeats and saves a two-time-base reconciliation snapshot;
unhealthy delivery closes acceptance readiness. Owner configuration provisions
no identity, policy or custody. Existing v1 databases migrate atomically to v2;
old memo UI releases require a new version. The first browser profile is English
organizational approval; unsupported locale/step/level refuses before rendering.
344 automated checks pass, including actual Flex Auth, Approval Engine and
Audit Core components. Twelve Chromium checks exercise local HTTPS, synthetic
PKCE login, cookies, entitlement, escaped packet content, acknowledgment bypass,
return, responsive layout, a single accepted entry/reload, audit delivery,
caller refusal and sign-out. The browser caught `no-referrer` suppressing the
form Origin; review pages now preserve same-origin headers while auth/downloads
remain no-referrer. Missing/null/foreign form origins and bad CSRF still refuse.
Plain-text native caller 401/403 responses also retain their refusal meaning.
Evidence: `docs/evidence/2026-09-11-protected-browser-review.json` and the
accompanying browser receipt/screenshots. This is disposable component/browser
proof, **not native human login, admitted policy/custody, deployment or factory
execution**. Factory attempts and paid calls remain zero.
**Next within T08:** obtain owner admission against
`docs/flex-auth-review-contract.md` for the exact production package/pins,
caller and assignment source. Admit native review-sender custody with
AUDIT-WP-0009-T11, registration rollout, service packaging/private state,
backup/restore and uncertain-entry operating procedure; then exercise the
deployed callback and actual human binding against the admitted Approval Engine.
German UI acceptance (PR-60), broader product steps/awareness controls and the
specified evidence export remain product work under this live task. They must
not be silently claimed by the bounded factory profile. The exact operational
setup and remaining limits are in `docs/protected-browser-review.md`.
T08 remains `progress`; no residual has been hidden by finishing the workplan.
## Known risks
- **T02 is a hard gate.** Writing the blueprint before the layer ruling risks