The RAILIANCE-WP migration numbered from RPF-WP-0001 without checking whether the target prefix was already in use. It was: this repository already had RPF-WP records, and the migration collided at 0018, 0019 and 0020, putting two unrelated workplans on each identifier. Central was left holding mixed records — rpf-wp-0018 carried the status of one file and the backing path of the other, because the reset processed two files claiming one identifier. The three files the migration displaced move to 0025-0027; the pre-existing records keep their numbers. Projection UUIDs are re-derived. Refs STATE-WP-0083-T05 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2.4 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | origin | origin_ref | state_hub_workstream_id | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RPF-WP-0026 | workplan | Adopt canonical flex-auth credential-grant checks | financials | railiance-platform | finished | codex | railiance | 2026-08-23 | 2026-08-23 |
|
routed | State Hub decision 1f9f257d-c9f2-4a5e-a018-8058a3f2a51a | 7677326a-04db-52ef-b05c-967dabe1759e |
RPF-WP-0026 — canonical flex-auth credential-grant checks
Goal
Adopt flex-auth's single canonical POST /v1/check decision surface for
credential-grant preflight without exposing credential values or adding a
consumer-specific flex-auth endpoint.
T01 — Resolve translation ownership
id: RPF-WP-0026-T01
status: done
priority: high
state_hub_task_id: "07f3fead-76d6-5e53-9a7b-9930560182d9"
The operator explicitly approved Option A in State Hub decision
1f9f257d-c9f2-4a5e-a018-8058a3f2a51a: railiance-platform maps its grant
metadata to CheckRequest and reads DecisionEnvelope. Duration parsing and
normalization belong here, before the flex-auth policy boundary.
T02 — Implement the canonical request and response
id: RPF-WP-0026-T02
status: done
priority: high
state_hub_task_id: "659ac0ee-c2b7-56fc-80d8-92b2fcf30e7b"
Change the helper default to /v1/check, emit the coordinated
tenant:platform / credential-grant:<id> / issue request vocabulary, send
requested_ttl_seconds as an integer, and accept only effect: allow.
Completed in source. Actor classes map to canonical subject types (Human,
Agent, or Automation); the bound subject and non-secret actor metadata are
carried in context. Missing, deny, redact, audit-only, and not-applicable
effects all fail closed. An allow also requires a non-empty decision id,
evaluator provenance, and subject/resource binding back to the request.
T03 — Verify and route the contract
id: RPF-WP-0026-T03
status: done
priority: medium
state_hub_task_id: "8f6b7481-e8c2-56eb-98b5-c49cae562d60"
Exercise focused allow and deny tests, validate the complete repository suite, and route the adopted mapping to flex-auth without requesting live credentials or a production mutation.
Completed with 70 focused credential tests, all credential-helper dry-runs, credential-catalog validation, and the complete 146-test offline suite passing. No flex-auth production endpoint was called and no credential was issued.