Register informed-decision-sitting-requester as create-only.
#67 -Commit
1620ce2edd
pushed by
tegwick
Implement scoped P06 authentication policy and guarded optional onboarding
#65 -Commit
e0b3c25f06
pushed by
tegwick
Implement P05 checked services and safe selected delivery recovery
#63 -Commit
aa709fb854
pushed by
tegwick
Verify reader scope before accepting absence of enrolled factors
#55 -Commit
113f3a6296
pushed by
tegwick
Require confirmed enrollment and genuine OTP evidence for MFA
#53 -Commit
122a0d1369
pushed by
tegwick
Support provider credential renewal and reject unsuccessful OTP validation
#51 -Commit
632b1f1376
pushed by
tegwick
Support opt-in MFA per browser client with authoritative enrollment checks
#49 -Commit
ac8ed65203
pushed by
tegwick
Allow registered provider redirects after sign-out confirmation
#48 -Commit
4d8b8fe934
pushed by
tegwick
Preserve browser Origin on the confirmed sign-out form
#47 -Commit
91efb6d988
pushed by
tegwick
Add central login recovery and confirmed shared sign-out
#46 -Commit
074c2ce498
pushed by
tegwick
Forward fresh-login requirements to the authentication provider
#45 -Commit
8d4336e944
pushed by
tegwick
Carry the tenant claim's provenance, and correct a guard the ruling voided
#42 -Commit
63d646b594
pushed by
tegwick
Make the static-registration precondition a checked condition
#41 -Commit
5f516a0fbb
pushed by
tegwick
Reject service-identity fields a browser client silently ignores
#40 -Commit
74b35b6107
pushed by
tegwick
Let a human token carry the zone it is issued into, without relabelling anyone
#39 -Commit
329e48f64a
pushed by
tegwick
Answer the approver-client questions, and fix what checking them turned up
#38 -Commit
a73da29093
pushed by
tegwick
feat(oidc): prepare one-shot upstream issuer proof without token disclosure
#37 -Commit
6f33abddcf
pushed by
tegwick
Require typed issuer refusals in live registration verification
#36 -Commit
dcebd46fa6
pushed by
tegwick
Ship the live-registration check both blocked tasks depend on
#35 -Commit
2a8735173b
pushed by
tegwick
Establish the live state and find a rollout precondition for G10
#34 -Commit
7dda967c27
pushed by
tegwick
Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions
#33 -Commit
7c9ed852ff
pushed by
tegwick
Reconcile packaging, bootstrap and migration credential handling
#32 -Commit
3b72834bca
pushed by
tegwick
Give the runtime real readiness, graceful shutdown and stated limits
#31 -Commit
d568b79223
pushed by
tegwick
Prove the migration against live directories and fix what that surfaced
#29 -Commit
e729ad4c28
pushed by
tegwick
Make the replacement harness runnable and target a live issuer
#28 -Commit
7534552754
pushed by
tegwick
Make snapshot attribute validation enforce a real rule
#27 -Commit
21acb5cdd6
pushed by
tegwick
Make the Keycloak transform preserve or name every policy field
#26 -Commit
e9fc8544ab
pushed by
tegwick