Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
45 lines
2.9 KiB
Markdown
45 lines
2.9 KiB
Markdown
# Email acknowledgment implementation — 2026-09-28
|
|
|
|
Existing task RTEL-WP-0002-T04 holds this work; no task/workplan added.
|
|
User decision f149e316-4ef4-4855-8453-bc9cdc938aad approves email to
|
|
bernd.worsch@gmail.com, explicit receipt confirmation, Railiance admin role,
|
|
audit-core evidence and controlled drills. Subsequent direction selected From
|
|
platform@coulomb.social and confirmed the mailbox needs setup.
|
|
|
|
Implemented WSGI acknowledgment, immutable first receipt, atomic SQLite audit
|
|
outbox, bounded audit transport, OIDC code/PKCE sessions, native Flex Auth
|
|
binding/digest/lifetime checks, Waitress runtime and background audit draining.
|
|
GET is inert; POST requires verified human/platform/admin identity, a fresh PDP
|
|
allow, Origin and CSRF. Email links identify occurrences, not bearer credentials.
|
|
|
|
Validation: 33 core tests with actual audit-core 3e42ca8 ingestion, including
|
|
accepted/lost-reply/reopened-store/duplicate; seven runtime tests with signed RSA
|
|
issuer fixtures, complete browser flow and the actual Flex Auth evaluator.
|
|
Synthetic identities/credentials do not prove production login or custody.
|
|
Native Alertmanager 0.28.1 template render passed. Hash-pinned runtime container
|
|
built; network-isolated read-only container returned HTTP 200 health and exited
|
|
cleanly on SIGTERM. Package candidates reside in rapp-telemetry/acknowledgment.
|
|
Policy and browser client registration candidates reside in integration/.
|
|
|
|
Native changes: identity-provisioner verified tegwick's requested email and added
|
|
only railiance-admins, preserving other memberships. KeyCape 1164f65 maps that
|
|
explicit group to railiance-admin without granting platform-operator. Full Go
|
|
suite passed. Published immutable image:
|
|
sha256:6f79a2af1c695d39480173fad013facd84d21e7732860366af519302a2c496b8.
|
|
NetKingdom manifest server dry-run passed; diff changed only the image (plus
|
|
metadata). Deployment rolled out successfully. Signed role remains unverified
|
|
until a real login. No Kubernetes Secret values were read or printed.
|
|
|
|
Remaining gates: mailbox setup; scoped SMTP/webhook/audit custody and receiver
|
|
registration; safe OIDC client registration and enforced policy caller admission;
|
|
application rollout; native login and actual failure/absence emails, Bernd's
|
|
acknowledgments and independent audit readback; outside-node watchdog and
|
|
recurring backups. Existing owner client helpers read complete Kubernetes
|
|
Secrets and cannot be used under the current environment orientation's rule.
|
|
No live email or acknowledgment is claimed. Workplan stays blocked, T04 wait.
|
|
|
|
Subsequently the founder created platform@coulomb.social and requested an OpenBao
|
|
entry, with the password to be added by the founder as a new version. Platform
|
|
helper scripts/telemetry_smtp_entry.py is silent, CAS=0, never reads credential
|
|
values, and preserves any existing version. Four unit tests pass. Attended
|
|
founder OIDC/MFA execution is requested; no native KV creation is yet claimed.
|