Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
51 lines
1.9 KiB
Markdown
51 lines
1.9 KiB
Markdown
---
|
|
id: RPF-WP-0032
|
|
type: workplan
|
|
title: "Design secrets-engine service JWT login"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: finished
|
|
owner: codex
|
|
created: "2026-09-05"
|
|
updated: "2026-09-05"
|
|
state_hub_workstream_id: "bd036850-e1bf-5b70-bbc3-683dfa4b125c"
|
|
---
|
|
|
|
# Design secrets-engine service JWT login
|
|
|
|
## Prepare the platform design
|
|
|
|
```task
|
|
id: RPF-WP-0032-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "166ece0b-840b-54b8-b10c-45f96eda0429"
|
|
```
|
|
|
|
Reviewed owner source and the current platform CCR contract. Delivered
|
|
`docs/credential-lane-designs/secrets-engine-service-jwt.md` with proposed exact scope, custody, lifecycle, implementation gaps,
|
|
approval requirements and positive/negative acceptance evidence. This is a
|
|
completed design deliverable, not a live lane or approval. No secrets accessed,
|
|
production objects changed or owner messages sent.
|
|
|
|
## Obtain owner inputs and implement the approved lane
|
|
|
|
```task
|
|
id: RPF-WP-0032-T02
|
|
status: cancel
|
|
priority: high
|
|
state_hub_task_id: "d1f4a9f6-4ea5-5daa-97bb-039856855bc2"
|
|
```
|
|
|
|
Confirm issuer, verification endpoint, actual KeyCape registration and live auth mount survey. Approve the login-only role/self policy, implement reviewed declarative support and prove effective-policy, wrong-claim, expiry and cleanup checks. Native lane execution still requires its separate exact authorization and scoped authority.
|
|
|
|
Review the linked design and pin current source revisions before implementation.
|
|
Do not interpret this workplan or a proposed coordinate as live authorization.
|
|
|
|
## Portfolio review — 2026-09-05
|
|
|
|
The design deliverable is complete. The implementation obligation is preserved
|
|
in **RPF-WP-0035-T02**, the single credential-lane implementation queue.
|
|
T02 is `cancel` here only because it is superseded there; it is not implemented,
|
|
waived or externally accepted. The approved design scope and all existing
|
|
identifiers remain unchanged. Archived on 2026-09-05 after this consolidation.
|