key-cape/workplans/KEY-WP-0012-userinfo-canonical-subject-resolution.md
tegwick 153258b9d3
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 23s
Fix UserInfo canonical subject resolution
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-08-31 23:41:29 +02:00

1 KiB

id type title domain repo status owner topic_slug created updated
KEY-WP-0012 workplan Repair UserInfo canonical subject resolution infotech key-cape active codex userinfo-canonical-subject-resolution 2026-08-31 2026-08-31

Repair subject lookup

id: KEY-WP-0012-T01
status: done
priority: high

Resolve the canonical LDAP-DN sub emitted by the token endpoint without passing it to the username-only repository lookup. Preserve stable subject semantics and verify any preferred_username lookup against the canonical ID.

Regression verification

id: KEY-WP-0012-T02
status: done
priority: high

Cover canonical-ID, legacy username-sub, missing subject, and suspended-user behavior. Run the KeyCape test suite and image build checks.

Deploy and verify OpenBao OIDC

id: KEY-WP-0012-T03
status: progress
priority: high

Publish and deploy the corrected KeyCape image, prove /userinfo accepts a fresh human access token, then resume the governed Policy Nexus bootstrap.