repo.work.assign_missing_identifiers

source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
repo-manager 2026-09-01 01:36:20 +02:00
parent 3ed3a391d6
commit b8dda4115a

View file

@ -9,6 +9,7 @@ owner: codex
topic_slug: userinfo-canonical-subject-resolution
created: "2026-08-31"
updated: "2026-09-01"
state_hub_workstream_id: "2aca83d8-4e80-52c6-8929-f1e957576b47"
---
## Repair subject lookup
@ -17,6 +18,7 @@ updated: "2026-09-01"
id: KEY-WP-0012-T01
status: done
priority: high
state_hub_task_id: "bc1ee2c7-a321-5914-96d1-9cb871f0ee1b"
```
Resolve the canonical LDAP-DN `sub` emitted by the token endpoint without
@ -29,6 +31,7 @@ semantics and verify any `preferred_username` lookup against the canonical ID.
id: KEY-WP-0012-T02
status: done
priority: high
state_hub_task_id: "7073cc30-a518-5c27-acaf-1a323fd981c6"
```
Cover canonical-ID, legacy username-sub, missing subject, and suspended-user
@ -40,6 +43,7 @@ behavior. Run the KeyCape test suite and image build checks.
id: KEY-WP-0012-T03
status: done
priority: high
state_hub_task_id: "571c5237-93fa-5c61-87af-974e02fd8929"
```
Publish and deploy the corrected KeyCape image, prove `/userinfo` accepts a