Open INFD-WP-0004 and draft the flex-auth list-action request (INFD-IN-0008)

The live overview is refused on every row: compact-sitting v2 gates read
with a 900 s MFA window and does not name the T03 memos. Propose a
limited-disclosure list action with a comfortable bar; read and every act
stay strict.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 359683@bnt-lap001
Assistant-Session: eebdc939-7a9b-4e50-9d39-c8437e8a14ec
This commit is contained in:
tegwick 2026-09-21 22:45:07 +02:00
parent 77792fa4f5
commit c9c05e595b
3 changed files with 245 additions and 0 deletions

View file

@ -443,3 +443,34 @@ description: >-
repository takes Staff either way and is not asking to be moved.
state_hub_intake_id: "01a0c23e-bd53-7ee0-9357-b223aa554842"
```
## INFD-IN-0008 — Admit a `list` action so decisions can be reviewed comfortably
```yaml
id: INFD-IN-0008
kind: intake
title: Admit a `list` action so decisions can be reviewed comfortably
status: open
origin: demand
origin_ref: INFD-WP-0004
priority: high
owner: flex-auth
repo: informed-decision
lane: blue
tags:
- cross-repo
- policy-request
created: '2026-09-21'
updated: '2026-09-21'
description: >-
The INFD-WP-0003 decision overview asks Flex Auth for `read` on each memo, and
the served compact-sitting v2 package refuses every row in production. Its
900-second MFA window is designed for binding, and KeyCape carries forward
earlier authentication timestamps (INFD-IN-0005). It also does not name the
three SECRETS-WP-0010-T03 memos. ASK: admit a `list` action with the same
identity bar minus freshness. It should cover memos from both admitted
packages, preferably as compact-sitting v3 with a resource-type-wide scope.
`read` and every act stay unchanged. Full request, disclosure limits and
fixtures: docs/flex-auth-request-list-action.md.
```