Commit graph

251 commits

Author SHA1 Message Date
6bcc2a5919 Synchronize session work records
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:16:31 +02:00
custodian-sync
672da6ff7d chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-14:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:11:48 +02:00
e17b3f4631 Record deployed P06 policy and completed platform acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:10:25 +02:00
e0b3c25f06 Implement scoped P06 authentication policy and guarded optional onboarding
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m22s
Authentication acceptance / provider-contract (push) Successful in 14s
Build and Publish Container Image / build-and-push (push) Successful in 41s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:00:05 +02:00
aa709fb854 Implement P05 checked services and safe selected delivery recovery
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m1s
Authentication acceptance / provider-contract (push) Successful in 13s
Build and Publish Container Image / build-and-push (push) Successful in 36s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 22:11:49 +02:00
187c49abe5 Pin final P04 release and native ownership-lock evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:30:50 +02:00
63b3070853 Refuse multi-owner factors and lock ownership during recovery
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m5s
Authentication acceptance / provider-contract (push) Successful in 13s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:21:24 +02:00
custodian-sync
30cd99cad1 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:19:55 +02:00
a10c2f7f98 Record completed P04 recovery rollout and acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:19:13 +02:00
d15f4dde0b Reconcile recovery by support reference and bound provider lookup
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m4s
Authentication acceptance / provider-contract (push) Successful in 14s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:11:03 +02:00
cb51584f58 Connect P04 audited recovery to fresh-MFA platform browser flow
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m14s
Authentication acceptance / provider-contract (push) Successful in 13s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 21:05:33 +02:00
custodian-sync
317d897b85 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:31:15 +02:00
4d893ed3c2 Verify factor identity again after recovery mutation
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m6s
Authentication acceptance / provider-contract (push) Successful in 12s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:30:23 +02:00
3b7df9047e Implement audited lost-factor recovery and track remaining P04 acceptance
All checks were successful
Authentication acceptance / acceptance (push) Successful in 58s
Authentication acceptance / provider-contract (push) Successful in 14s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:28:45 +02:00
custodian-sync
244e7e096f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:25:26 +02:00
502a2d5c56 Retain provider acceptance CI and synchronized assurance task binding
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:06:32 +02:00
custodian-sync
7f3a6da042 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:05:13 +02:00
ecca6cb4ba Record verified enrollment assurance release and automate provider contract tests
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m13s
Authentication acceptance / provider-contract (push) Successful in 28s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:03:44 +02:00
113f3a6296 Verify reader scope before accepting absence of enrolled factors
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m6s
Build and Publish Container Image / build-and-push (push) Successful in 53s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:59:09 +02:00
122a0d1369 Require confirmed enrollment and genuine OTP evidence for MFA
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m10s
Build and Publish Container Image / build-and-push (push) Successful in 41s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:37:08 +02:00
custodian-sync
3a36f1a507 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:26:53 +02:00
74b4f7f1bc Establish scoped KeyCape factor custody and verified automatic renewal
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:25:33 +02:00
custodian-sync
fd34ac98f0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:28:27 +02:00
78f5a718e9 Record provider credential renewal release and remaining owner handoff
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:27:35 +02:00
custodian-sync
f4d8e44f0b chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:24:50 +02:00
632b1f1376 Support provider credential renewal and reject unsuccessful OTP validation
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m10s
Build and Publish Container Image / build-and-push (push) Successful in 44s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:23:24 +02:00
85f5deaf4a Support opt-in MFA per browser client with authoritative enrollment checks
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 00:28:09 +02:00
custodian-sync
9a226e9cd0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-13:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 00:27:39 +02:00
ac8ed65203 Support opt-in MFA per browser client with authoritative enrollment checks
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 00:27:28 +02:00
e1e292919a Record generated State Hub recovery task bindings
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 17:10:41 +02:00
custodian-sync
51f2bad145 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-12:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 17:10:02 +02:00
62a86a4ba0 Record live account recovery and browser sign-out verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:50:35 +02:00
4d8b8fe934 Allow registered provider redirects after sign-out confirmation
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 41s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:47:33 +02:00
91efb6d988 Preserve browser Origin on the confirmed sign-out form
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 35s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:43:32 +02:00
074c2ce498 Add central login recovery and confirmed shared sign-out
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 44s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:34:41 +02:00
custodian-sync
89694ad6df chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-12:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 03:20:30 +02:00
22788787c1 Record attended fresh-login rollout and verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 03:12:45 +02:00
custodian-sync
d68389861e chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-12:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:55:27 +02:00
0647301c03 Record published fresh-login image and attended rollout gate
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:53:55 +02:00
custodian-sync
7695a064bc chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-12:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:45:56 +02:00
8d4336e944 Forward fresh-login requirements to the authentication provider
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 44s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:43:31 +02:00
139994cfac chore(consistency): register KEY-WP-0032 and refresh records [auto]
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 23:07:49 +02:00
custodian-sync
c09937dcb4 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-10:
  - update .custodian-brief.md for key-cape

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 23:07:35 +02:00
b66ce13e4e Close G10, the last of the ten assessment gaps
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 35s
Every closure criterion now has evidence, taken one at a time rather than as an
impression. Custody admitted and provisioned (CCR-2026-0017/0018, both secrets
wired, receipt committed). The real callback registered, verified live by its
owner, pinned by test. The new contracts deployed and verified at the 2026-09-09
attended rollout: acceptance passed at generation 38, per-client live JWKS
verification, exact claims, excess-scope and wrong-secret denial, human consume
denied, no credential values emitted. Token types reconciled at the consumer
boundary -- ops-warden took option (a) because the proxy's OpenBao token and an
issuer JWT were never one thing to cut over between; both lanes owner-confirmed
and no route changed. Four handoff receipts retained.

The condition that named the gap -- source capability running ahead of live
custody and consumer adoption -- no longer holds.

What closing it does not claim, stated in both documents: the approver
registration is published, not deployed, so the human approval path is registered
rather than proved; the deployed image predates most of this revision; the
verifier receipt declines real predecessor rotation and observed wall-clock
expiry and so do we; and the Qonto rotation is deferred by owner decision on
evidence. Those are open items with owners and triggers, which is a different
thing from a gap between what this repository claims and what is true.

SCOPE's header lineage is consolidated so a reader can ask what changed since a
given revision and get an answer, and the test count is refreshed rather than
carried.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 23:06:57 +02:00
f247d3529d Close T04 and pin the single route by which a principal becomes human
KEY-WP-0014-T04 sat `wait` with nothing outstanding, which is a contradiction.
Its title is admit rotation and verify consumer handoff, and both are delivered:
the semantics are published, the executor, authority and transport are named, the
CCR will be prepared on request, and step 4 shipped as keycape verify-client;
ops-warden took option (a) for the reason given, with both lanes owner-confirmed
and no route changed. Executing a rotation was never its deliverable, so treating
the owner's deferral as an open item would have kept the task open against work
it was not scoped to do. The deferral stands separately, revisited on evidence.

GH-DEC-2026-016 §5 applies A-16 to what makes a principal human. Verified against
source that `human` has exactly one route here -- a literal on the
authorization-code path after an upstream login resolved to a directory user,
with no configuration able to assert it -- so A-16 does not yet bite and no
provenance claim is warranted. Adding one would encode a distinction that does
not exist.

Asserting the behaviour would not protect that: a test checking a human token
says human passes just as happily when the value starts coming from a
registration. The guard parses the package and requires every principal_type
assignment to be a string literal, the set being exactly human and service. It
covers both shapes -- the browser path assigns into a map, the service path uses
a key-value pair in a map literal -- and checking only assignments found one of
two routes and passed, which the pinned literal set caught. Verified by mutation.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 23:05:16 +02:00
11bd9fb2bb chore(consistency): refresh work records [auto]
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 22:51:04 +02:00
custodian-sync
2957b02d27 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-09-10:
  - update .custodian-brief.md for key-cape

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 22:50:51 +02:00
c9bb7fac58 Register the approver client now its callback exists
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 47s
informed-decision submitted client_id informed-decision-approver and redirect
https://decisions.coulomb.social/auth/callback, with the origin already live and
verified by them rather than reported: both / and /auth/callback return 200 on a
Let's Encrypt certificate valid to 2026-12-09. The host is decisions, not the
decide of an earlier draft. Its path serves a placeholder for now, which does not
matter -- the redirect is matched as an exact string and never fetched.

Published as a public authorization_code client with S256 PKCE, audience
approval-engine, scopes openid/approval:read/approval:approve, mfaRequired true
and a declared tenant:platform. No secretRef, since PKCE is the whole proof.

TestApproverRegistrationShapeIsExact pins every field, so widening a scope or
relaxing MFA fails the build rather than reading as an edit, and asserts the
registration passes startup validation -- proving the KEY-WP-0028 tenant
exemption holds for the registration that actually depends on it.

Two existing guards fired on the way in and neither was loosened. The tenant pin
refused an unreviewed client carrying a tenant, which is its purpose, so the
approver was added to its reviewed set deliberately. And the audience test
panicked slicing secretRef[4:], an assumption that held while the fixture had
only confidential clients; the approver is the first public one, so the loop now
guards on the env: prefix.

The declared tenant reaches the token by the GH-DEC-2026-013 gap route by
construction, and tenant_source says so: registration, never directory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-10 22:50:13 +02:00
f9812ab3b2 Carry approval-engine's store-isolation limit into the tenant contract
approval-engine chose the registration-bound shape for the consuming side and
asked that the limit making it admissible be carried into the contract rather
than left in a message.

Their check is store isolation -- does this caller belong to the store this
engine serves -- not membership. A registration-supplied tenant is admissible for
that question. It is not admissible for any doctrine turning on the approver's own
membership, which is a fact about the person that this claim cannot carry, and an
exact-match check does not become that claim merely by matching.

That is GH-DEC-2026-013 section 1 reached independently from the consuming side,
and it is the practical reason tenant_source exists: a consumer whose check means
store isolation can accept registration, one whose check means membership must
require directory. Recorded next to the provenance table so the two are read
together.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-10 13:44:02 +02:00
324b5e056d Record the owner decision: Qonto rotation deferred, not refused
The repository owner declined to schedule the rotation now. Recorded with the
reasoning rather than as a bare status so it is revisited on evidence instead of
re-litigated: nothing indicates compromise, the offer stands open, and one
founder-attended window is already pending for the fail-closed startup changes.

Names what should reopen it -- an actual or suspected exposure, the secret's age
becoming a stated concern, a consumer requiring proof of rotation, or a decision
to prove rotation step 4 before relying on it -- and says plainly that a calendar
date is not one of them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad
2026-09-10 09:15:48 +02:00