Record Binky MFA login acceptance

This commit is contained in:
tegwick 2026-07-29 22:05:18 +02:00
parent 72b0eb404c
commit abd9e6fa2b

View file

@ -163,6 +163,15 @@ to the new platform-operator role. Commit `90a2078` adds and tests the explicit
Ready. The operator must start a fresh OIDC session so the corrected claims Ready. The operator must start a fresh OIDC session so the corrected claims
are minted. are minted.
2026-07-29 human acceptance: the Binky administrator completed the reusable
password setup, enrolled a privacyIDEA TOTP factor, and successfully signed in
through KeyCape with password plus OTP. Enrollment revealed that privacyIDEA's
default QR label exposed only the token serial. The live
`coulomb-friendly-token-labels` enrollment policy now emits issuer `Coulomb`
and label `{user}@{realm}` for future tokens; existing authenticator entries
must be renamed locally because wallets do not accept remote label updates.
Final claim/denial evidence remains.
## Task: Register a workload-identity OIDC client for the qonto runtime ## Task: Register a workload-identity OIDC client for the qonto runtime
```task ```task