Commit graph

100 commits

Author SHA1 Message Date
custodian-sync
cdfb046b80 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-23:
  - update .custodian-brief.md for key-cape

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e3f-7301-7622-9be1-12e5f352881c
2026-08-23 13:00:52 +02:00
0a7cc7e9e9 Refresh WORK-RECORDS after KEY-WP-0008 closeout 2026-08-16 01:06:27 +02:00
custodian-sync
bd90a0e82c chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for key-cape
2026-08-16 01:06:09 +02:00
b6af6c5268 Finish KEY-WP-0008: registration handoff and client MFA isolation
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
Add signed registration/enrollment handoffs, per-request assurance
policy with login-session isolation, and /logout. coulomb-social
stays AAL1 unless acr_values or another client raises the bar.
2026-08-16 01:05:27 +02:00
fff9e39478 docs: point at RMASTER-WP-0019 after master prefix rename 2026-08-14 14:29:19 +02:00
3bef507cb8 KEY-WP-0008: honor per-client mfaRequired and acr_values step-up
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 30s
Allow coulomb-social ordinary login at AAL1 via mfaRequired: false while
keeping provider requireForAll for clients without an override. Preserve
explicit acr_values=aal2 for step-up.
2026-08-09 22:42:51 +02:00
custodian-sync
8e976bc60f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for key-cape
2026-08-09 21:56:59 +02:00
custodian-sync
460dcbce0d chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for key-cape
2026-08-09 20:52:35 +02:00
cd33e118c0 Add coulomb-social public OIDC client to KeyCape dev-config
Aligns local compose client list with live railiance01 registration.
2026-08-09 01:50:52 +02:00
09aafdb9c6 Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout)
Maintainer decision, 2026-07-29: adopts TRSL V1C1 as this repo's
preliminary governing license, per target-revenue's
workplans/TREV-WP-0008-governance-and-pilot-rollout.md T05. Full
specialist legal review is deferred until out of beta (target-revenue
SCOPE.md §1). No Phase is yet declared for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-29 23:48:58 +02:00
a6ff5384b1 Finish portal OIDC integration 2026-07-29 22:59:38 +02:00
custodian-sync
6b32fb1384 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-29:
  - update .custodian-brief.md for key-cape
2026-07-29 22:55:54 +02:00
custodian-sync
253a5bac77 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-29:
  - update .custodian-brief.md for key-cape
2026-07-29 22:15:20 +02:00
2465481e3c Complete Binky tenant onboarding 2026-07-29 22:13:53 +02:00
abd9e6fa2b Record Binky MFA login acceptance 2026-07-29 22:05:18 +02:00
72b0eb404c Record platform-root authorization fix 2026-07-29 21:33:37 +02:00
90a20783e5 Map platform-root group to platform operator
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 26s
2026-07-29 21:30:56 +02:00
41d2e1d1f6 Record Binky password handoff readiness 2026-07-28 17:56:14 +02:00
49a8992d6e Advance Binky human onboarding 2026-07-28 16:49:27 +02:00
custodian-sync
2bfd115f11 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-28:
  - update .custodian-brief.md for key-cape
2026-07-28 16:48:13 +02:00
070c38f447 Record suspended identity enforcement 2026-07-28 01:33:24 +02:00
909bb327fc Deny suspended directory identities
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 24s
2026-07-28 01:23:22 +02:00
76da0237ff Bind portal OIDC workplan to State Hub 2026-07-28 00:43:56 +02:00
custodian-sync
806bcf18d4 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-28:
  - update .custodian-brief.md for key-cape
2026-07-28 00:40:13 +02:00
e8b4eded88 Map explicit tenant groups into OIDC claims
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 26s
2026-07-28 00:34:19 +02:00
993a4dd589 Register user-engine portal OIDC client 2026-07-28 00:06:38 +02:00
401ab9ca55 Refresh Binky onboarding records 2026-07-27 22:34:21 +02:00
custodian-sync
c9459b29fc chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for key-cape
2026-07-27 22:31:59 +02:00
1cd137cd9d Route Binky onboarding through user portal 2026-07-27 22:31:43 +02:00
3d108adeb8 Refresh work record index 2026-07-27 21:13:44 +02:00
custodian-sync
3def97b087 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for key-cape
2026-07-27 20:53:36 +02:00
e54bcd9a40 Advance Binky identity onboarding 2026-07-27 20:39:13 +02:00
custodian-sync
0fa9ec9673 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for key-cape
2026-07-27 20:18:33 +02:00
881fffc079 Complete KeyCape service-token rollout
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 25s
2026-07-27 20:17:55 +02:00
custodian-sync
f4a2f7eb1e chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for key-cape
2026-07-27 20:03:36 +02:00
custodian-sync
e4464278e7 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - KEY-WP-0006-T04: progress → wait
2026-07-27 20:03:31 +02:00
e877d2752d Implement KeyCape service-token issuance
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 47s
2026-07-27 20:03:07 +02:00
custodian-sync
519f0772d2 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-27:
  - update .custodian-brief.md for key-cape
2026-07-27 19:39:07 +02:00
86e6c083f7 Define Qonto runtime identity contract 2026-07-26 13:34:56 +02:00
custodian-sync
739b1f5c72 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-26:
  - update .custodian-brief.md for key-cape
2026-07-26 13:09:56 +02:00
custodian-sync
a32512c6de chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-26:
  - update .custodian-brief.md for key-cape
2026-07-26 11:03:32 +02:00
9ce84b915f chore(consistency): sync WORK-RECORDS.md for KEY-WP-0005 closure [auto]
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:18:50 +02:00
custodian-sync
f4da182a1f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-24:
  - update .custodian-brief.md for key-cape
2026-07-24 00:18:41 +02:00
44da5f5f99 KEY-WP-0005-T02-T03: cached tenant_roles claim, close workplan
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m21s
New internal/adapters/tenantengine package, mirroring
internal/adapters/{lldap,privacyidea,authelia}'s shape: Client.Roles()
calls tenant-engine's cache-read endpoint. Fails open by construction --
unreachable, non-200, malformed body, or a nil *Client all return
(nil, false), never an error to specially handle. Wired into
TokenHandler.TenantEngine (nil by default, existing tests unaffected);
token.go stamps tenant_roles only when ok.

7 adapter tests plus 3 TokenHandler-level tests proving the actual
required behavior end-to-end: present when reachable, token issuance still
200 with every other core claim intact when unreachable (tenant_roles
simply absent -- the literal done-criteria), absent when not configured.

Real bug found and fixed at the source, not worked around: the first live
cross-process check (real flex-auth, real tenant-engine, this adapter)
returned tenant_not_found for a tenant that existed -- tenant-engine's read
endpoint was keyed by its internal tenant_id, but key-cape only ever has
the tenant's profile identifier. Fixed in tenant-engine
(ADHOC-2026-07-24), re-verified with the same live three-process chain --
roles=[IAM] ok=true.

Workplan closed: T01-T03 done. Explicitly still open: client_credentials /
service-token issuance -- no such flow exists in token.go at all, a
materially larger separate piece of work than either task here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:18:17 +02:00
fb888579dc chore(consistency): sync WORK-RECORDS.md for KEY-WP-0005-T01 [auto]
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:04:09 +02:00
custodian-sync
f66df69202 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-24:
  - update .custodian-brief.md for key-cape
2026-07-24 00:03:59 +02:00
f1f7fa9dd7 KEY-WP-0005-T01: IAM Profile core claims for the human PKCE flow
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m50s
Verified first: grant_types_supported advertises client_credentials in
discovery.go, but token.go only ever accepted authorization_code -- no
service-token issuance path exists at all. Building one from scratch is
materially bigger than extending the existing flow; explicitly not
attempted here, left open in the workplan rather than declared done.

What shipped for the human Authorization Code + PKCE flow:

- domain.User.Tenant (new, omitempty) + token.go's effectiveTenant():
  falls back to tenant:coulomb (this workstation's actual tenant, ADR-0006)
  when unset -- never an empty tenant claim, never a silent reassignment.
- principal_type: "human", unconditional.
- groups/roles promoted from scope-gated to unconditional core claims,
  always [] not null when empty. One pre-existing test asserted the old
  scope-gated groups behavior -- updated to match the new intentional
  behavior, not left failing or reverted.
- assurance built from PKCESession.MFAVerified (new field, threaded
  through completeAuthorization's two call sites in authorize.go) --
  whether MFA was actually verified in this session, not static enrollment
  state. aal2 only when required-and-passed this time, aal1 otherwise.

go build/vet clean, go test ./... green repo-wide. Two new authorize_test.go
cases assert MFAVerified on both paths. tests/profile/profile_test.go's
TestCompleteTokenFlow (the repo's own full HTTP integration test) extended
with real value assertions for all five claims, not just presence checks.

Python conformance tool not run against a live instance (needs the full
Authelia+LLDAP+privacyIDEA stack); TestCompleteTokenFlow's real HTTP round
trip covers the equivalent claim checks instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 00:03:31 +02:00
custodian-sync
e51a2d74e9 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-07-23:
  - update .custodian-brief.md for key-cape
2026-07-23 23:52:35 +02:00
8059f65a1b chore(consistency): write back state_hub ids for KEY-WP-0005 [auto]
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 23:52:13 +02:00
cca7434b2d chore(consistency): register KEY-WP-0005 in State Hub [auto]
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:48:04 +02:00