Implement authenticated alert receipt acknowledgments and audit delivery

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:11:33 +02:00
parent 67283b66c2
commit e7282e493d
25 changed files with 1881 additions and 0 deletions

View file

@ -112,3 +112,28 @@ failure/absence acknowledgments, an outside-node watchdog and recurring backup
ownership. The founder, Bernd Worsch, supplies recipient/admission decisions;
rapp-telemetry and platform own runtime/custody integration. No additional task
or workplan was opened, and no live schedule or notification was enabled.
September 28 recipient decision: Bernd Worsch confirmed email to
`bernd.worsch@gmail.com`, requested the `railiance-admin` role for that user,
explicit link-based confirmation and acknowledgment records in audit-core, and
authorized controlled failure/absence drills. Recipient/channel choice is no
longer a blocker. The native directory group membership is now applied; the updated KeyCape
issuer is deployed. A real signed-role login remains unproved.
Implemented the bounded acknowledgment component, email link template and audit
outbox/transport under this same T04. A GET never acknowledges; authenticated
human role, fresh policy decision, Origin and CSRF checks precede POST. The first
acknowledgment and audit envelope commit together; retries retain the same event.
Actual audit-core receiver code accepts then deduplicates after a lost reply and
process reopen. See `docs/alert-acknowledgment.md` for the concrete owner bindings.
OIDC code/PKCE sessions, a native Flex Auth decision adapter, a background audit
worker and the package-owned container/manifests are now implemented. The native
policy evaluator and signed issuer fixtures pass. KeyCape 1164f65 is published
and deployed; the native directory role grant preserves existing memberships.
T04 stays wait/blocked: the founder selected From `platform@coulomb.social` and
subsequently created the mailbox; password custody remains pending. Dedicated SMTP/webhook/audit custody, OIDC
client and enforced PDP caller admission, application rollout, signed identity,
real email/acknowledgment and independent audit readback remain. Outside-node
watchdog and recurring backup gates remain. No new task/workplan was created.