Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
1.8 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated |
|---|---|---|---|---|---|---|---|---|---|
| KEY-WP-0035 | workplan | Opt-in MFA for demo-company login | infotech | key-cape | active | codex | infotech | 2026-09-13 | 2026-09-13 |
Requested behavior: password-only login before OTP activation; require OTP after activation. Do not lower assurance of unrelated applications.
Implement enrollment-dependent browser policy
id: KEY-WP-0035-T01
status: done
priority: high
Add mfaOptional, preserve explicit AAL2 and existing client policy, fail closed on
provider lookup errors and malformed/incomplete responses. Preserve the setting
in config/runtime/canonical model and flag manual migration requirements.
Validation: go test ./... and git diff --check passed on 2026-09-13. See docs/optional-mfa.md.
Restore authoritative factor lookup and enable the reviewed client
id: KEY-WP-0035-T02
status: wait
priority: high
Live factor-read credentials return HTTP 401. The owner route net-kingdom-privacyidea-admin-token is non-resolvable pending railiance-platform's approved custody/renewal contract (NK-WP-0033). Native credential handoff required; no secrets in work records. Do not enable the policy before lookup is verified. Prepare exact byte-preserving client migration after the provider contract is available; deploy digest-pinned source and run no-factor/enrolled/error checks.
Verify optional enrollment and account management access
id: KEY-WP-0035-T03
status: wait
priority: high
Verify provider self-service login, possession-confirmed activation, cancellation and removal/recovery. Resolve shared portal assurance scope before surfacing the verified OTP setup link. Actual user login acceptance remains open under KEY-WP-0034 and VERGABE-WP-0019; this work does not finish either workplan.