|
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 31s
The exporter discovered groups by walking each user's memberships, so a group nobody belongs to never reached the snapshot, and a failed lookup was skipped by a `continue` under a comment claiming it was recorded in the incompatibility report. The run then emitted `result: "success"`. Add an optional `domain.GroupLister` capability and implement `ListGroups` on the LLDAP adapter as a direct group-subtree search, kept off `UserRepository` because the OIDC layer never enumerates the directory. Record `groupEnumeration` on every result and a `Complete()` predicate over it; abort rather than write a smaller snapshot when the enumeration fails; report a failed per-user lookup on the fallback path; emit `partial` telemetry and name the mode from the CLI. Reading the adapter to write this surfaced a defect the assessment had not listed: `LookupGroups` never populated `Group.Members`, and the exporter built every membership from that field, so against a real directory the `memberships` block was always empty while the fixture-backed tests passed. Memberships on the fallback path now come from the user/group pair actually observed. Sort users, groups and memberships so an unchanged directory exports identically. Closes G05 of the scope/intent assessment. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012WAsfsfQmDu4vcBhiMcmQp Assistant: claude-code Assistant-Model: opus Assistant-Process: 867844@bnt-lap001 Assistant-Session: 3d45905e-0016-4b49-b828-231406881f7b |
||
|---|---|---|
| .. | ||
| ADHOC-2026-09-05.md | ||
| ADHOC-2026-09-07.md | ||
| KEY-WP-0001-keycape-implementation.md | ||
| KEY-WP-0002-container-image-gitea.md | ||
| KEY-WP-0003-bootstrap-console-oidc-mfa-login.md | ||
| KEY-WP-0004-binky-hedgehog-tenant-onboarding.md | ||
| KEY-WP-0005-iam-profile-core-claims.md | ||
| KEY-WP-0006-client-credentials-service-tokens.md | ||
| KEY-WP-0007-user-engine-portal-oidc-client.md | ||
| KEY-WP-0008-registration-handoff-and-client-mfa-policy.md | ||
| KEY-WP-0009-provider-capabilities-and-service-identities.md | ||
| KEY-WP-0010-openbao-operator-loopback-callback.md | ||
| KEY-WP-0011-live-secret-exposure-recovery.md | ||
| KEY-WP-0012-userinfo-canonical-subject-resolution.md | ||
| KEY-WP-0013-approval-engine-resource-audience.md | ||
| KEY-WP-0014-native-credential-lane-handoff.md | ||
| KEY-WP-0015-scope-intent-assessment.md | ||
| KEY-WP-0016-authorization-code-protocol-hardening.md | ||
| KEY-WP-0017-canonical-model-and-discovery-conformance.md | ||
| KEY-WP-0018-export-completeness-evidence.md | ||