From abd9e6fa2bb6a83edbc9aeb676e49cb38b6bad68 Mon Sep 17 00:00:00 2001 From: tegwick Date: Wed, 29 Jul 2026 22:05:18 +0200 Subject: [PATCH] Record Binky MFA login acceptance --- .../KEY-WP-0004-binky-hedgehog-tenant-onboarding.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md index 4db0aa1..8fa2980 100644 --- a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md +++ b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md @@ -163,6 +163,15 @@ to the new platform-operator role. Commit `90a2078` adds and tests the explicit Ready. The operator must start a fresh OIDC session so the corrected claims are minted. +2026-07-29 human acceptance: the Binky administrator completed the reusable +password setup, enrolled a privacyIDEA TOTP factor, and successfully signed in +through KeyCape with password plus OTP. Enrollment revealed that privacyIDEA's +default QR label exposed only the token serial. The live +`coulomb-friendly-token-labels` enrollment policy now emits issuer `Coulomb` +and label `{user}@{realm}` for future tokens; existing authenticator entries +must be renamed locally because wallets do not accept remote label updates. +Final claim/denial evidence remains. + ## Task: Register a workload-identity OIDC client for the qonto runtime ```task