Require declared human control in factory credential delivery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-10 20:16:55 +02:00
parent d1c13b5dd6
commit 2b0d04e8e1
11 changed files with 451 additions and 27 deletions

View file

@ -49,7 +49,7 @@ synthetic exec-env transport proof passed; no real secret was read.
id: SECRETS-WP-0009-T03
status: wait
priority: high
blocking_reason: "Recipient binding now implemented and proved with the real local approval/PDP chain. Complete exact private owner configuration and native MessagesOwner holder admission, CCR-2026-0019 operator reader, human/audit/service path and scoped live delivery. CCR-2026-0020 was cancelled by its owner."
blocking_reason: "Recipient binding and declared human-control request/PEP enforcement implemented and proved with the real local approval/PDP chain. Complete exact private owner configuration and native MessagesOwner holder admission, CCR-2026-0019 operator reader, human/audit/service path and scoped live delivery. CCR-2026-0020 was cancelled by its owner."
state_hub_task_id: "f8069c8a-ad6b-5d0b-9a36-c2326699437d"
```
@ -238,3 +238,30 @@ from operator-owned creation, parent custody and cleanup. No automatic cleanup
or live reader proof is claimed. The exact group remains NetKingdom/KeyCape's
return, followed by reviewed attended admission and positive/negative evidence.
T03 stays wait; no identity, role, secret, runtime or route readiness changed.
### 2026-09-10 declared human-control consumer return
Consumed APPROVAL-WP-0002's GH-DEC-2026-016 implementation and schema-v5 release.
The existing human action-review requirement is explicit on the factory catalog:
`approval.human_control: true`. The CheckRequest carries that intent in its bound
context; the consumer requires exact true in the served claim before PDP and
again afterward. The internal consume binding carries the observed declaration.
Missing service coordinates, ordinary lane approval, stage and unsafe-demo paths
cannot substitute for the declared control. Undeclared lanes retain their behavior.
The catalog's exec owner stays pending; no policy, role or credential was changed.
Validation: 388 tests pass, including 27 new strict-type, missing/false claim,
request binding, post-PDP recheck, fallback and actual exec-handler cases.
The real local KeyCape/Approval Engine/Flex Auth exercise passes 22 checks.
The request API declares true; KeyCape service binding is refused; an undeclared
claim reaches no PDP/consume/backend; declared positive delivery consumes before
the synthetic backend/child. Positive human evidence is an explicit store fixture,
not a native human JWT or browser login. Evidence and repeatable command:
`docs/evidence/2026-09-10-human-control-consumer-exercise.json`,
`tools/exercise_approval_identity.py --exec-owner --human-control`.
This closes consumer source adoption. T03 still requires the narrow native
requester, INFD T07/T08 functional browser and human approval, audit custody,
CCR-2026-0019 operator binding/attended read, current deployed service/PDP and
configured MessagesOwner/native delivery. HFACT T01/T04/T05 retains factory
config/G0 and natural queue/model proof. No native secret read or paid attempt.