All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 23s
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
1 KiB
1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated |
|---|---|---|---|---|---|---|---|---|---|
| KEY-WP-0012 | workplan | Repair UserInfo canonical subject resolution | infotech | key-cape | active | codex | userinfo-canonical-subject-resolution | 2026-08-31 | 2026-08-31 |
Repair subject lookup
id: KEY-WP-0012-T01
status: done
priority: high
Resolve the canonical LDAP-DN sub emitted by the token endpoint without
passing it to the username-only repository lookup. Preserve stable subject
semantics and verify any preferred_username lookup against the canonical ID.
Regression verification
id: KEY-WP-0012-T02
status: done
priority: high
Cover canonical-ID, legacy username-sub, missing subject, and suspended-user behavior. Run the KeyCape test suite and image build checks.
Deploy and verify OpenBao OIDC
id: KEY-WP-0012-T03
status: progress
priority: high
Publish and deploy the corrected KeyCape image, prove /userinfo accepts a
fresh human access token, then resume the governed Policy Nexus bootstrap.