net-kingdom/sso-mfa
tegwick 17a66fe236
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed
Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization
was reusing an existing kc_login cookie's IssuedAt as authTime even after
a freshly-validated MFA token in the same request, which understated
freshness for downstream binding-grade checks (flex-auth's 900s review
window denied informed-decision's infd-20260927-b01 approval as a result).
See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md.
Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 19:20:06 +02:00
..
bootstrap NET-WP-0020 finished: attended-ceremony + auto-unseal-transit profiles, greenfield init/unseal proof 2026-07-02 22:08:33 +02:00
k8s Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed 2026-09-27 19:20:06 +02:00
WORKPLAN.md docs(sso-mfa): record T04 blocker — wrong image reference (ImagePullBackOff) 2026-03-20 17:16:35 +00:00