Record flex-auth digest contract fix
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
tegwick 2026-08-23 14:38:51 +02:00
parent 70371649af
commit 01b45ab8b3

View file

@ -212,9 +212,8 @@ OpenBao while State Hub lacks the durable endpoint. Legacy local decisions are
reachable for prod-labeled lanes only with an explicit unsafe-demo switch,
disabled Hub URL, and loopback OpenBao. The throwaway scripts declare that
exception. Live destroy remains disabled independently. State Hub endpoint and
authenticated approval storage are still outstanding; the flex-auth example's
committed digest was also found stale against its Go `CheckRequest` encoder and
must be corrected upstream.
authenticated approval storage are still outstanding. flex-auth corrected its
example digest and added a complete binding regression assertion in `d402408`.
Define and enforce the decision contract needed by production commands. A
resolved approval must bind at least: