key-cape/src/internal
tegwick 11ce29af8b
All checks were successful
Authentication acceptance / acceptance (push) Successful in 1m27s
Authentication acceptance / provider-contract (push) Successful in 14s
Build and Publish Container Image / build-and-push (push) Successful in 52s
Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033).
Authelia 4.38 refuses prompt=login for every real login because it registers
the authorization request after authentication. Send a bounded max_age
upstream and check the verified upstream auth_time against prompt=login /
max_age in the callback, failing closed when auth_time is missing.

Also update the service-client example count left stale by 651625c/1620ce2.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 352750@bnt-lap001
Assistant-Session: de41ef1c-2113-4dd2-9b92-f318ffa7f98b
2026-09-23 21:59:21 +02:00
..
adapters Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033). 2026-09-23 21:59:21 +02:00
authclient Require typed issuer refusals in live registration verification 2026-09-08 16:46:02 +02:00
config Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033). 2026-09-23 21:59:21 +02:00
domain Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033). 2026-09-23 21:59:21 +02:00
errors feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00
jose chore(consistency): sync KEY-WP-0019 completion [auto] 2026-09-07 09:02:05 +02:00
migration Support opt-in MFA per browser client with authoritative enrollment checks 2026-09-13 00:27:28 +02:00
server Enforce login freshness in KeyCape instead of forwarding prompt=login (KEY-WP-0033). 2026-09-23 21:59:21 +02:00
validator Prove the migration against live directories and fix what that surfaced 2026-09-08 00:29:34 +02:00