Record Binky password handoff readiness
This commit is contained in:
parent
49a8992d6e
commit
41d2e1d1f6
1 changed files with 8 additions and 0 deletions
|
|
@ -148,6 +148,14 @@ reset delivery. First-password handoff, MFA enrollment, and final human-token
|
|||
claim/denial evidence remain. No operator-set password or raw credential was
|
||||
used as a shortcut.
|
||||
|
||||
2026-07-28 update: the reusable password handoff is now live at the canonical
|
||||
KeyCape host and is issued/renewed through the user-engine administration UI.
|
||||
Links are opaque, expire after 15 minutes, are single use, and older links are
|
||||
revoked on renewal. A disposable-user live test proved password registration,
|
||||
directory login, replay denial, and cleanup. This task now awaits only the
|
||||
Binky user's own password choice, MFA enrollment, and final scoped-token
|
||||
acceptance.
|
||||
|
||||
## Task: Register a workload-identity OIDC client for the qonto runtime
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue