Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization was reusing an existing kc_login cookie's IssuedAt as authTime even after a freshly-validated MFA token in the same request, which understated freshness for downstream binding-grade checks (flex-auth's 900s review window denied informed-decision's infd-20260927-b01 approval as a result). See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md. Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 169987@bnt-lap001 Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999 |
||
|---|---|---|
| .. | ||
| bootstrap | ||
| k8s | ||
| WORKPLAN.md | ||