Advance pre-cutover identity conformance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-28 16:48:47 +02:00
parent c639306c53
commit a58df4c3e6
5 changed files with 53 additions and 5 deletions

View file

@ -157,7 +157,7 @@ outage, suspension, restore, and browser/MFA matrix remains.
```task
id: NK-WP-0023-T07
status: wait
status: progress
priority: high
state_hub_task_id: "a574dcec-f7cd-417b-aeaa-5392a7428241"
```
@ -168,6 +168,14 @@ OIDC/PKCE + MFA, and verify the Binky-only tenant-admin token and lifecycle
controls. Publish only non-secret evidence to `KEY-WP-0004-T02/T07`, then
finish that workplan.
2026-07-28: the deployed versioned portal API created the Binky tenant-admin
user and membership and provisioned/linked its LLDAP identity. The provider
correctly reports `password_setup_required`. During this flow a newline in the
mounted trusted-proxy Secret proved HTTP-incompatible; user-engine `0ef2ae5`
normalizes runtime transport whitespace, has 105 passing tests, and is live.
LLDAP SMTP is not configured, so first-password handoff and MFA/claim
acceptance remain rather than falling back to an operator-set password.
## T08 - Document enterprise integration extension points
```task