Record Binky password handoff readiness

This commit is contained in:
tegwick 2026-07-28 17:56:14 +02:00
parent 49a8992d6e
commit 41d2e1d1f6

View file

@ -148,6 +148,14 @@ reset delivery. First-password handoff, MFA enrollment, and final human-token
claim/denial evidence remain. No operator-set password or raw credential was claim/denial evidence remain. No operator-set password or raw credential was
used as a shortcut. used as a shortcut.
2026-07-28 update: the reusable password handoff is now live at the canonical
KeyCape host and is issued/renewed through the user-engine administration UI.
Links are opaque, expire after 15 minutes, are single use, and older links are
revoked on renewal. A disposable-user live test proved password registration,
directory login, replay denial, and cleanup. This task now awaits only the
Binky user's own password choice, MFA enrollment, and final scoped-token
acceptance.
## Task: Register a workload-identity OIDC client for the qonto runtime ## Task: Register a workload-identity OIDC client for the qonto runtime
```task ```task