Record flex-auth digest contract fix
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
tegwick 2026-08-23 14:38:51 +02:00
parent 70371649af
commit 01b45ab8b3

View file

@ -212,9 +212,8 @@ OpenBao while State Hub lacks the durable endpoint. Legacy local decisions are
reachable for prod-labeled lanes only with an explicit unsafe-demo switch, reachable for prod-labeled lanes only with an explicit unsafe-demo switch,
disabled Hub URL, and loopback OpenBao. The throwaway scripts declare that disabled Hub URL, and loopback OpenBao. The throwaway scripts declare that
exception. Live destroy remains disabled independently. State Hub endpoint and exception. Live destroy remains disabled independently. State Hub endpoint and
authenticated approval storage are still outstanding; the flex-auth example's authenticated approval storage are still outstanding. flex-auth corrected its
committed digest was also found stale against its Go `CheckRequest` encoder and example digest and added a complete binding regression assertion in `d402408`.
must be corrected upstream.
Define and enforce the decision contract needed by production commands. A Define and enforce the decision contract needed by production commands. A
resolved approval must bind at least: resolved approval must bind at least: