Require typed issuer refusals in live registration verification
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-08 16:46:02 +02:00
parent 471465df22
commit dcebd46fa6
6 changed files with 168 additions and 13 deletions

View file

@ -19,13 +19,23 @@ exact deployment-owned callback, `audience: approval-engine`,
consume or other approval grants to that client. No callback is invented here.
The ID token is for the login client; present the access token to approval-engine.
These fragments are not live registrations. Deployment requires custody-managed
values for the named environment references, the exact human callback, and a
rollout of this version. Never log the token or secret. Verify the resulting
These fragments are not live registrations. The two service registrations require
custody-managed values for the named environment references and a reviewed
rollout of this version, including the upstream issuer precondition. Platform's
CCR-2026-0017/0018 use OpenBao field `CLIENT_SECRET`; their approval remains open.
The separate human registration needs its actual UI-owned callback. A bearer-only
approval resource server has no such callback; its absence does not prevent
service-client issuance or service startup, and service credentials cannot be
counted as human approval evidence. Never log the token or secret. Verify the resulting
access token against the deployed issuer's `/jwks`, checking issuer, audience,
expiry, subject, principal type, tenant, roles, scope and assurance. Verify that
operator consume and human consume requests are rejected. Local tests verify
signatures against the JWKS handler; they do not constitute live issuance proof.
Negative verification requires the token endpoint's typed refusal: HTTP 400,
`invalid_profile_usage`, feature `scope` for excess scope; HTTP 401 with feature
`Authorization` for a predecessor secret. A timeout, 5xx, malformed response,
invalid signature or JWKS failure is not proof of denial.
KeyCape owns issuance and client grants/disablement. OpenBao and the deployment
operator own credential custody; approval-engine enforces its resource policy.

View file

@ -15,7 +15,7 @@ requests:
scopes: [approval:read, approval:consume]
lifetime: 15m
proposed_openbao_path: platform/workloads/secrets-engine/approval-client
field: client_secret
field: CLIENT_SECRET
proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client
kubernetes_key: client-secret
keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
@ -27,7 +27,7 @@ requests:
scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit]
lifetime: 15m
proposed_openbao_path: platform/workloads/approval-engine/operator-client
field: client_secret
field: CLIENT_SECRET
proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client
kubernetes_key: client-secret
keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
@ -35,6 +35,8 @@ requests:
consumer: approval-engine-operator
human_registration:
status: awaiting-exact-callback
blocks_service_client_rollout: false
owner: unassigned-approver-ui
scopes: [openid, approval:approve]
mfa_required: true
client_type: public
@ -65,4 +67,13 @@ verification:
blockers:
- Admit exact custody paths, field delivery, consumer identities and lifecycle authority.
- Resolve attended first-provision authority through the custody owner.
- Supply exact human client ID and callback URI.
- Verify the actual upstream ID-token issuer before production image rollout.
custody_return:
owner_record: railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md#Admit-KeyCape-approval-engine-client-custody-and-delivery
requests: [CCR-2026-0017, CCR-2026-0018]
status: proposed-awaiting-owner-approval
field_correction: CLIENT_SECRET
scope: KeyCape verifier-side copies only; client-side retrieval is not admitted.
human_registration_gate:
- The approver UI owner must supply its real client ID and exact callback.
- This gate blocks human approval entry; it does not block the two independent client_credentials registrations or service startup.