Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed
Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization was reusing an existing kc_login cookie's IssuedAt as authTime even after a freshly-validated MFA token in the same request, which understated freshness for downstream binding-grade checks (flex-auth's 900s review window denied informed-decision's infd-20260927-b01 approval as a result). See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md. Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 169987@bnt-lap001 Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
This commit is contained in:
parent
2f1e6c3369
commit
17a66fe236
1 changed files with 5 additions and 4 deletions
|
|
@ -51,10 +51,11 @@ spec:
|
|||
containers:
|
||||
- name: keycape
|
||||
# Image published to the self-hosted Forgejo OCI registry (KEY-WP-0002).
|
||||
# NK-WP-0041-T02 path B, key-cape@3b0446e: the in-cluster token call
|
||||
# sends the public HTTPS origin. Staged while Authelia stays 4.38.
|
||||
# Rollback: sha256:82f1e5ac481e4f963dbd4b05256aee75412c9e9b465d31c9356f5d17f26a6897
|
||||
image: forgejo.coulomb.social/coulomb/key-cape@sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3
|
||||
# key-cape@911e9de: completeAuthorization no longer backdates a
|
||||
# freshly-verified MFA to a stale kc_login cookie's IssuedAt
|
||||
# (INFD-IN-0005).
|
||||
# Rollback: sha256:7aefcee9b79eb3285997066b323ae1772e13d58f875aacc6eb5e9407bd1c1185
|
||||
image: forgejo.coulomb.social/coulomb/key-cape@sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e
|
||||
imagePullPolicy: IfNotPresent
|
||||
|
||||
ports:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue