|
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s
KEY-WP-0019-T05 rested on "existing tests pass unchanged", which shows the move onto internal/jose preserved behaviour but not that the behaviour is checked. Disabling the RSA comparison in jose.Verify fails both callers' suites, so the shared verifier is load-bearing on each path. Correct the comment on the caller-side cases added with the move. It claimed the existing tamper case fails on the signature segment's shape before any key is used; it does not — appending eight characters leaves a decodable segment, so that case does reach and does check the signature. The two new cases are still worth their place for what a byte-level tamper cannot reach: a structurally valid token signed by an unpublished key under a published kid tests that key selection is bound to the key set, and an undersized modulus in the published set tests that ParseJWKS strictness denies rather than falling through to the claims. Record both in the workplan and in G01's status. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012WAsfsfQmDu4vcBhiMcmQp Assistant: claude-code Assistant-Model: opus Assistant-Process: 867844@bnt-lap001 Assistant-Session: 3d45905e-0016-4b49-b828-231406881f7b |
||
|---|---|---|
| .. | ||
| ADHOC-2026-09-05.md | ||
| ADHOC-2026-09-07.md | ||
| KEY-WP-0001-keycape-implementation.md | ||
| KEY-WP-0002-container-image-gitea.md | ||
| KEY-WP-0003-bootstrap-console-oidc-mfa-login.md | ||
| KEY-WP-0004-binky-hedgehog-tenant-onboarding.md | ||
| KEY-WP-0005-iam-profile-core-claims.md | ||
| KEY-WP-0006-client-credentials-service-tokens.md | ||
| KEY-WP-0007-user-engine-portal-oidc-client.md | ||
| KEY-WP-0008-registration-handoff-and-client-mfa-policy.md | ||
| KEY-WP-0009-provider-capabilities-and-service-identities.md | ||
| KEY-WP-0010-openbao-operator-loopback-callback.md | ||
| KEY-WP-0011-live-secret-exposure-recovery.md | ||
| KEY-WP-0012-userinfo-canonical-subject-resolution.md | ||
| KEY-WP-0013-approval-engine-resource-audience.md | ||
| KEY-WP-0014-native-credential-lane-handoff.md | ||
| KEY-WP-0015-scope-intent-assessment.md | ||
| KEY-WP-0016-authorization-code-protocol-hardening.md | ||
| KEY-WP-0017-canonical-model-and-discovery-conformance.md | ||
| KEY-WP-0018-export-completeness-evidence.md | ||
| KEY-WP-0019-upstream-provider-token-verification.md | ||