Align native CLI execution with approved T03 targets and authority
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 03:21:48 +02:00
parent 09422db079
commit 25a7d71cf5
8 changed files with 90 additions and 8 deletions

View file

@ -188,3 +188,14 @@ pins — and that pin has not been created, so the PDP call is not wired yet.
- It does not render or cache an authorization decision.
- It does not infer consumption from a decision record or from local
evidence.
### Native CLI authority and target correction — 2026-09-14
The CLI now submits the catalog's explicit policy and AppRole targets, matching
its frozen review inputs. After a valid native claim/PDP join, it retains the
actual PDP decision id for evidence and still requires successful CAS consume.
The catalog CCR reference remains provenance; the native path does not demand a
second hub decision or local fixture with that CCR identifier. Unserved legacy
build/test paths retain their existing review gate. Claim, PDP, human-control,
stance, freshness and consume refusals still prevent backend access.