--- id: KEY-WP-0012 type: workplan title: "Repair UserInfo canonical subject resolution" domain: infotech repo: key-cape status: active owner: codex topic_slug: userinfo-canonical-subject-resolution created: "2026-08-31" updated: "2026-08-31" --- ## Repair subject lookup ```task id: KEY-WP-0012-T01 status: done priority: high ``` Resolve the canonical LDAP-DN `sub` emitted by the token endpoint without passing it to the username-only repository lookup. Preserve stable subject semantics and verify any `preferred_username` lookup against the canonical ID. ## Regression verification ```task id: KEY-WP-0012-T02 status: done priority: high ``` Cover canonical-ID, legacy username-sub, missing subject, and suspended-user behavior. Run the KeyCape test suite and image build checks. ## Deploy and verify OpenBao OIDC ```task id: KEY-WP-0012-T03 status: progress priority: high ``` Publish and deploy the corrected KeyCape image, prove `/userinfo` accepts a fresh human access token, then resume the governed Policy Nexus bootstrap.