1.5 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | depends_on | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| KEY-WP-0007 | workplan | User-engine portal OIDC relying-party integration | infotech | key-cape | active | codex | netkingdom | 2026-07-27 | 2026-07-27 |
|
KEY-WP-0007 - User-engine portal OIDC relying-party integration
Register and prove the reusable user-engine portal as a strict KeyCape public
client. This is the authentication edge required by NK-WP-0023-T03; it does
not move user-domain or authorization ownership into KeyCape.
Register the static portal client
id: KEY-WP-0007-T01
status: progress
priority: high
Register user-engine-portal for authorization code with mandatory S256 PKCE,
exact callback URIs and only openid profile email groups. No wildcard,
implicit flow, client secret, or dynamic registration is allowed.
Deploy and verify the live client
id: KEY-WP-0007-T02
status: wait
priority: high
Update the railiance01 KeyCape configuration without exposing its signing key or backend credentials. Verify discovery, authorize redirect validation, unregistered callback denial and successful token exchange through the portal.
Prove claims and MFA isolation
id: KEY-WP-0007-T03
status: wait
priority: high
Prove issuer, audience, tenant, groups, roles and assurance claims are verified by the portal and that tenant administration does not imply platform-root. Complete the Binky user/MFA acceptance through the reusable browser path.