|
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
serviceSubject and roles are read only on the client_credentials path. On a browser client they are accepted and then ignored, since subject and roles come from the directory user -- so a registration that looks effective fails later as a downstream rejection rather than as a registration defect. tokenLifetime was already rejected this way, so the rule existed and was incomplete. Nothing in dev-config, the example fixture or the live deployment sets either field on a browser client, checked against all three rather than assumed, so this breaks no existing configuration. tenant is deliberately excluded, and a test pins that: a browser client may declare one, and humanTenant resolves it against the directory, refusing issuance when they disagree (KEY-WP-0013-T05). An earlier version of this change rejected tenant too and would have made that feature unusable. It started from T05's blocker paragraph, which was accurate when written and already fixed by the time this task began -- blocker prose ages faster than the code it describes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6 |
||
|---|---|---|
| .. | ||
| ADHOC-2026-09-05.md | ||
| ADHOC-2026-09-07.md | ||
| KEY-WP-0001-keycape-implementation.md | ||
| KEY-WP-0002-container-image-gitea.md | ||
| KEY-WP-0003-bootstrap-console-oidc-mfa-login.md | ||
| KEY-WP-0004-binky-hedgehog-tenant-onboarding.md | ||
| KEY-WP-0005-iam-profile-core-claims.md | ||
| KEY-WP-0006-client-credentials-service-tokens.md | ||
| KEY-WP-0007-user-engine-portal-oidc-client.md | ||
| KEY-WP-0008-registration-handoff-and-client-mfa-policy.md | ||
| KEY-WP-0009-provider-capabilities-and-service-identities.md | ||
| KEY-WP-0010-openbao-operator-loopback-callback.md | ||
| KEY-WP-0011-live-secret-exposure-recovery.md | ||
| KEY-WP-0012-userinfo-canonical-subject-resolution.md | ||
| KEY-WP-0013-approval-engine-resource-audience.md | ||
| KEY-WP-0014-native-credential-lane-handoff.md | ||
| KEY-WP-0015-scope-intent-assessment.md | ||
| KEY-WP-0016-authorization-code-protocol-hardening.md | ||
| KEY-WP-0017-canonical-model-and-discovery-conformance.md | ||
| KEY-WP-0018-export-completeness-evidence.md | ||
| KEY-WP-0019-upstream-provider-token-verification.md | ||
| KEY-WP-0020-migration-contract-preservation.md | ||
| KEY-WP-0021-snapshot-attribute-validation.md | ||
| KEY-WP-0022-replacement-harness-and-external-conformance.md | ||
| KEY-WP-0023-live-migration-proof.md | ||
| KEY-WP-0024-tenant-roles-opt-in-wiring.md | ||
| KEY-WP-0025-runtime-lifecycle-and-readiness.md | ||
| KEY-WP-0026-packaging-bootstrap-and-credential-handling.md | ||
| KEY-WP-0027-rollout-readiness-and-live-state.md | ||
| KEY-WP-0028-browser-client-field-validation.md | ||