key-cape/src
tegwick 11ce29af8b
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m27s
Authentication acceptance / provider-contract (push) Successful in 14s
Build and Publish Container Image / build-and-push (push) Successful in 52s
Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033).
Authelia 4.38 refuses prompt=login for every real login because it registers
the authorization request after authentication. Send a bounded max_age
upstream and check the verified upstream auth_time against prompt=login /
max_age in the callback, failing closed when auth_time is missing.

Also update the service-client example count left stale by 651625c/1620ce2.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 352750@bnt-lap001
Assistant-Session: de41ef1c-2113-4dd2-9b92-f318ffa7f98b
2026-09-23 21:59:21 +02:00
..
cmd Register informed-decision-sitting-requester as create-only. 2026-09-15 20:08:07 +02:00
internal Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033). 2026-09-23 21:59:21 +02:00
tests Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions 2026-09-08 10:22:52 +02:00
go.mod feat: implement T14, T10 — enforcement middleware, LLDAP adapter 2026-03-13 01:45:21 +01:00
go.sum feat: implement T14, T10 — enforcement middleware, LLDAP adapter 2026-03-13 01:45:21 +01:00
Makefile feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00